USN-5090-1

    Dashboard / Vulnerabilities / USN-5090-1

    USN-5090-1

    Published: 27 Sept 2021Last Modified: 22 Apr 2026

    Summary: apache2 vulnerabilities

    Details: James Kettle discovered that the Apache HTTP Server HTTP/2 module incorrectly handled certain crafted methods. A remote attacker could possibly use this issue to perform request splitting or cache poisoning attacks. (CVE-2021-33193) It was discovered that the Apache HTTP Server incorrectly handled certain malformed requests. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. (CVE-2021-34798) Li Zhi Xin discovered that the Apache mod_proxy_uwsgi module incorrectly handled certain request uri-paths. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 21.04. (CVE-2021-36160) It was discovered that the Apache HTTP Server incorrectly handled escaping quotes. If the server was configured with third-party modules, a remote attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-39275) It was discovered that the Apache mod_proxy module incorrectly handled certain request uri-paths. A remote attacker could possibly use this issue to cause the server to forward requests to arbitrary origin servers. (CVE-2021-40438)

    Affected packages

    Package

    Name: apache2

    Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.4.29-1ubuntu4.17

    Affected versions

    2.4.27-2ubuntu3
    2.4.29-1ubuntu1
    2.4.29-1ubuntu2
    2.4.29-1ubuntu3
    2.4.29-1ubuntu4
    2.4.29-1ubuntu4.1
    2.4.29-1ubuntu4.2
    2.4.29-1ubuntu4.3
    2.4.29-1ubuntu4.4
    2.4.29-1ubuntu4.5
    2.4.29-1ubuntu4.6
    2.4.29-1ubuntu4.7
    2.4.29-1ubuntu4.8
    2.4.29-1ubuntu4.10
    2.4.29-1ubuntu4.11
    2.4.29-1ubuntu4.12
    2.4.29-1ubuntu4.13
    2.4.29-1ubuntu4.14
    2.4.29-1ubuntu4.16

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-5090-1 | CVE-DB