CLSA-2022-1656430949

    Dashboard / Vulnerabilities / CLSA-2022-1656430949

    CLSA-2022-1656430949

    Published: 28 Jun 2022Last Modified: 4 Jun 2026

    Summary: Fix CVE(s): CVE-2022-28615, CVE-2022-26377, CVE-2022-30522, CVE-2022-30556, CVE-2022-31813

    Details: * SECURITY UPDATE: mod_sed may make excessively large memory allocations and trigger an abort - debian/patches/CVE-2022-30522.patch: limit mod_sed memory usage - CVE-2022-30522 * SECURITY UPDATE: HTTP request smuggling in mod_proxy_ajp - debian/patches/CVE-2022-26377.patch: parse request headers in the way so Transfer-Encoding has precedence over Content-Length - CVE-2022-26377 * SECURITY UPDATE: possible out-of-bounds read in ap_strcmp_match() with an extremely large input buffer - debian/patches/CVE-2022-28615.patch: use apr_size_t (e.g. long) for array indexing - CVE-2022-28615 * SECURITY UPDATE: mod_lua r:wsread() may return length that points past the end of the storage allocated for the buffer - debian/patches/CVE-2022-30556.patch: consistently use lua_websocket_readbytes() and check the return value - CVE-2022-30556 * SECURITY UPDATE: mod_proxy may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism - debian/patches/CVE-2022-31813.patch: preserve original request headers so an upstream knows what the original request hostname was - CVE-2022-31813

    Affected packages

    Package

    Name: apache2

    Purl: pkg:deb/tuxcare/apache2?distro=ubuntu-16.04

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1:2.4.18-2ubuntu3.17+tuxcare.els5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2022-1656430949 | CVE-DB