UBUNTU-CVE-2021-36160
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-36160
UBUNTU-CVE-2021-36160
Summary:
Details: A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
References: https://ubuntu.com/security/CVE-2021-36160, https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2021-36160, http://httpd.apache.org/security/vulnerabilities_24.html, https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70@%3Ccvs.httpd.apache.org%3E, https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d@%3Ccvs.httpd.apache.org%3E, https://ubuntu.com/security/notices/USN-5090-1, https://www.cve.org/CVERecord?id=CVE-2021-36160
Affected packages
Package
Name: apache2
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
