[ubuntu/focal-security] apache2 2.4.41-4ubuntu3.5 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Mon Sep 27 13:55:27 UTC 2021
apache2 (2.4.41-4ubuntu3.5) focal-security; urgency=medium
* SECURITY UPDATE: request splitting over HTTP/2
- debian/patches/CVE-2021-33193-pre1.patch: process early errors via a
dummy HTTP/1.1 request as well in modules/http2/h2.h,
modules/http2/h2_request.c, modules/http2/h2_session.c,
modules/http2/h2_stream.c.
- debian/patches/CVE-2021-33193-pre2.patch: sync with github standalone
version 1.15.17 in modules/http2/h2_bucket_beam.c,
modules/http2/h2_config.c, modules/http2/h2_config.h,
modules/http2/h2_h2.c, modules/http2/h2_headers.c,
modules/http2/h2_headers.h, modules/http2/h2_mplx.c,
modules/http2/h2_request.c, modules/http2/h2_stream.h,
modules/http2/h2_task.c, modules/http2/h2_task.h,
modules/http2/h2_version.h.
- debian/patches/CVE-2021-33193.patch: refactor request parsing in
include/ap_mmn.h, include/http_core.h, include/http_protocol.h,
include/http_vhost.h, modules/http2/h2_request.c, server/core.c,
server/core_filters.c, server/protocol.c, server/vhost.c.
- CVE-2021-33193
* SECURITY UPDATE: NULL deref via malformed requests
- debian/patches/CVE-2021-34798.patch: add NULL check in
server/scoreboard.c.
- CVE-2021-34798
* SECURITY UPDATE: DoS in mod_proxy_uwsgi
- debian/patches/CVE-2021-36160.patch: fix PATH_INFO setting for
generic worker in modules/proxy/mod_proxy_uwsgi.c.
- CVE-2021-36160
* SECURITY UPDATE: buffer overflow in ap_escape_quotes
- debian/patches/CVE-2021-39275.patch: fix ap_escape_quotes
substitution logic in server/util.c.
- CVE-2021-39275
* SECURITY UPDATE: arbitrary origin server via crafted request uri-path
- debian/patches/CVE-2021-40438-pre1.patch: faster unix socket path
parsing in the "proxy:" URL in modules/proxy/mod_proxy.c,
modules/proxy/proxy_util.c.
- debian/patches/CVE-2021-40438.patch: add sanity checks on the
configured UDS path in modules/proxy/proxy_util.c.
- CVE-2021-40438
apache2 (2.4.41-4ubuntu3.4) focal; urgency=medium
* d/p/lp-1930430-Backport-r1865740.patch: fix OCSP in proxy mode
(LP: #1930430)
Date: 2021-09-24 12:19:09.278552+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.5
-------------- next part --------------
Sorry, changesfile not available.
More information about the Focal-changes
mailing list