Bug 41826 - apache2: Multiple issues (4.1)
apache2: Multiple issues (4.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.1
Other Linux
: P3 normal (vote)
: UCS 4.1-3-errata
Assigned To: Philipp Hahn
Arvid Requate
:
Depends on:
Blocks: 41827 41828 43770
  Show dependency treegraph
 
Reported: 2016-07-20 18:28 CEST by Arvid Requate
Modified: 2017-03-09 14:09 CET (History)
2 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): External feedback, Security
Max CVSS v3 score:
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2016-07-20 18:28:53 CEST
Upstream Debian package version 2.2.22-13+deb7u7 fixes the following issue:

* The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httproxy" issue.  NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability. (CVE-2016-5387)

CVSS v2 base score 5 (AV:N/AC:L/Au:N/C:N/I:P/A:N)

Please note that the current package has been rebuilt with the additional Debian patches from deb7u6 (Bug #40929)
Comment 1 Florian Best univentionstaff 2016-08-23 18:34:03 CEST
Ticket#2016082321000687
Comment 2 Philipp Hahn univentionstaff 2016-09-28 10:44:37 CEST
repo_admin.py -U -r 4.1 -s errata4.1-3 -d wheezy -p apache2

r16746

Package: apache2
Version: 2.2.22-13.101.201609281005
Branch: ucs_4.1-0
Scope: errata4.1-3

r72849 | Bug #42491,Bug #32018 home: Fix umount
 apache2.yaml
Comment 3 Arvid Requate univentionstaff 2016-10-11 17:16:36 CEST
Verified:
* Package imported and built with existing patches
* OK: ucs-test -s apache -E dangerous
* Advisory Ok
Comment 4 Janek Walkenhorst univentionstaff 2016-10-12 13:06:46 CEST
<http://errata.software-univention.de/ucs/4.1/289.html>