Alpine: apache2: security update to 2.4.27-r1

high Tenable Self-Hosted Container Security Plugin ID 403537

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be
set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This
affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an
unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue
and thus secret data is not always sent, and the specific data depends on many factors including
configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in
server/core.c. (CVE-2017-9798)

See Also

https://security.alpinelinux.org/vuln/CVE-2017-9798

Plugin Details

Severity: High

ID: 403537

Version: Revision 1.27

Type: Local

Published: 10/31/2023

Updated: 11/19/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

Percentile: 96.51

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2017-9798

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 9/18/2017

Reference Information

CVE: CVE-2017-9798

BID: 100872, 105598