CVE-2016-0736 | Apache HTTP Server up to 2.4.24 mod_session_crypto Padding cryptographic issues (EDB-40961 / Nessus ID 100098)
A vulnerability classified as critical has been found in Apache HTTP Server up to 2.4.24. Affected is an unknown function of the component mod_session_crypto. The manipulation leads to cryptographic issues (Padding).
This vulnerability is traded as CVE-2016-0736. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.