openSUSE-SU-2022:1031-1
Dashboard / Vulnerabilities / openSUSE-SU-2022:1031-1
openSUSE-SU-2022:1031-1
Summary: Security update for apache2
Details: This update for apache2 fixes the following issues: - CVE-2022-23943: heap out-of-bounds write in mod_sed (bsc#1197098). - CVE-2022-22720: HTTP request smuggling due to incorrect error handling (bsc#1197095). - CVE-2022-22719: use of uninitialized value of in r:parsebody in mod_lua (bsc#1197091). - CVE-2022-22721: possible buffer overflow with very large or unlimited LimitXMLRequestBody (bsc#1197096).
References: https://lists.opensuse.org/archives/list/[email protected]/thread/4LVBWCEX7IVK73L73JHPXASP5AT5BZGS/, https://bugzilla.suse.com/1197091, https://bugzilla.suse.com/1197095, https://bugzilla.suse.com/1197096, https://bugzilla.suse.com/1197098, https://www.suse.com/security/cve/CVE-2022-22719, https://www.suse.com/security/cve/CVE-2022-22720, https://www.suse.com/security/cve/CVE-2022-22721, https://www.suse.com/security/cve/CVE-2022-23943
Affected packages
Package
Name: apache2
Purl: pkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
