BSA-2018-556
21658
20 September 2018
30 March 2018
Closed
Low
3.7
N/A
CVE-2017-15715
Summary
Security Advisory ID : BSA-2018-556
Component : Apache HTTPD
Revision : 2.0: Final
The expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename.
This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename
Affected Products
No Brocade Fibre Channel technology products from Broadcom are currently known to be affected by this vulnerability.
Revision History
Version | Change | Date |
---|---|---|
1.0 | Initial Publication | Mar 30, 2018 |
2.0 | Updated FOS | Sept 20, 2018 |