CLSA-2022-1648136327
Dashboard / Vulnerabilities / CLSA-2022-1648136327
CLSA-2022-1648136327
Summary: Fix CVE(s): CVE-2022-23943, CVE-2022-22720, CVE-2022-22721, CVE-2022-22719
Details: * SECURITY UPDATE: mod_lua Use of uninitialized value of in r:parsebody - debian/patches/CVE-2022-22719.patch: refactor lua_read_body() in order to catch all possible errors - CVE-2022-22719 * SECURITY UPDATE: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier - debian/patches/CVE-2022-22720.patch: simpler connection close logic if discarding the request body fails - CVE-2022-22720 * SECURITY UPDATE: Possible buffer overflow with very large or unlimited LimitXMLRequestBody - debian/patches/CVE-2022-22721.patch: make sure and check that LimitXMLRequestBody fits in system memory - CVE-2022-22721 * SECURITY UPDATE: mod_sed: Read/write beyond bounds - debian/patches/CVE-2022-23943.patch: use size_t to allow for larger buffer sizes and unsigned arithmetics and refactor logic flow of sed_write_output() - CVE-2022-23943 apache2 (1:2.4.18-2ubuntu3.17+tuxcare.els3) xenial-security; urgency=medium
Affected packages
Package
Name: apache2
Purl: pkg:deb/tuxcare/apache2?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
