CVE-2018-1312 log
| Source |
|
| Severity | Low |
| Remote | Yes |
| Type | Content spoofing |
| Description | In Apache httpd 2.2.0 before 2.4.30, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-664 | apache | 2.4.29-1 | 2.4.33-1 | Medium | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 04 Apr 2018 | ASA-201804-4 | AVG-664 | apache | Medium | multiple issues |