CLSA-2021-1639681846

    Dashboard / Vulnerabilities / CLSA-2021-1639681846

    CLSA-2021-1639681846

    Published: 16 Dec 2021Last Modified: 4 Jun 2026

    Summary: Fix CVE(s): CVE-2020-7071, CVE-2020-7068, CVE-2021-21705, CVE-2021-21704, CVE-2021-21703, CVE-2021-21702

    Details: * SECURITY UPDATE: Process crash and information disclosure - debian/patches/CVE-2020-7068.patch: fix access-after-free for actual_alias pointer - CVE-2020-7068 * SECURITY UPDATE: logic error due to invalid input validation - debian/patches/CVE-2020-7071.patch: add validation fo url->user field - CVE-2020-7071 * SECURITY UPDATE: program crash due to null pointer dereference - debian/patches/CVE-2021-21702.patch: pass empty string instead for NULL pointers to soap_error1(). Check NULL pointer in attr_is_equal_ex() and node_is_equal_ex() - CVE-2021-21702 * SECURITY UPDATE: integer overflow and subsequent incorrect buffer allocation - debian/patches/CVE-2021-21704.patch: add checks that prevent the overflow, replace strcat() with more secure strlcat() - CVE-2021-21704 * SECURITY UPDATE: logic error due to incorrect input validation - debian/patches/CVE-2021-21705.patch: fix validation of url password with FILTER_VALIDATE_URL parameter, - CVE-2021-21705 * SECURITY UPDATE: priv escalation due to shared memory between worker processes - debian/patches/CVE-2021-21703.patch: change scoreboard->proc type to array of structs and use scoreboard->nprocs only in child processes - CVE-2021-21703

    Affected packages

    Package

    Name: libapache2-mod-php7.0

    Purl: pkg:deb/tuxcare/libapache2-mod-php7.0?distro=ubuntu-16.04

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7.0.33-0ubuntu0.16.04.17

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2021-1639681846 | CVE-DB