Univention Bugzilla – Bug 54412
apache2: Multiple issues (4.4)
Last modified: 2022-02-02 16:40:33 CET
New Debian apache2 2.4.25-3+deb9u12A~4.4.8.202202021239 fixes: This update addresses the following issues: * possible NULL dereference or SSRF in forward proxy configurations (CVE-2021-44224) * mod_lua: possible buffer overflow when parsing multipart content (CVE-2021-44790)
--- mirror/ftp/4.4/unmaintained/component/4.4-8-errata/source/apache2_2.4.25-3+deb9u11A~4.4.8.202110040913.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/apache2_2.4.25-3+deb9u12A~4.4.8.202202021239.dsc @@ -1,9 +1,18 @@ -2.4.25-3+deb9u11A~4.4.8.202110040913 [Mon, 04 Oct 2021 09:22:08 +0200] Univention builddaemon <buildd@univention.de>: +2.4.25-3+deb9u12A~4.4.8.202202021239 [Wed, 02 Feb 2022 12:46:18 +0100] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 05-autostart-setting 10-apache2-reload 20-no-proxy + +2.4.25-3+deb9u12 [Tue, 01 Feb 2022 19:18:01 +0100] Anton Gladky <gladk@debian.org>: + + * Non-maintainer upload by the LTS Security Team. + * CVE-2021-44790: A buffer overflow in mod_lua may result in denial of service + or potentially the execution of arbitrary code. + * CVE-2021-44224: When operating as a forward proxy, Apache was depending on + the setup suspectible to denial of service or Server Side + Request forgery. 2.4.25-3+deb9u11 [Sat, 02 Oct 2021 15:27:55 +0200] Sylvain Beucler <beuc@debian.org>: <http://piuparts.knut.univention.de/4.4-8/#2984063162495493114>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] 94591673cd Bug #54412: apache2 2.4.25-3+deb9u12A~4.4.8.202202021239 doc/errata/staging/apache2.yaml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1168>