Univention Bugzilla – Bug 54580
apache2: Multiple issues (4.4)
Last modified: 2022-03-30 12:16:45 CEST
New Debian apache2 2.4.25-3+deb9u13A~4.4.8.202203230720 fixes: This update addresses the following issues: * mod_lua: Use of uninitialized value of in r:parsebody (CVE-2022-22719) * Errors encountered during the discarding of request body lead to HTTP request smuggling (CVE-2022-22720) * core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody (CVE-2022-22721) * mod_sed: Read/write beyond bounds (CVE-2022-23943)
--- mirror/ftp/4.4/unmaintained/component/4.4-8-errata/source/apache2_2.4.25-3+deb9u12A~4.4.8.202202021239.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/apache2_2.4.25-3+deb9u13A~4.4.9.202203231446.dsc @@ -1,9 +1,17 @@ -2.4.25-3+deb9u12A~4.4.8.202202021239 [Wed, 02 Feb 2022 12:46:18 +0100] Univention builddaemon <buildd@univention.de>: +2.4.25-3+deb9u13A~4.4.9.202203231446 [Wed, 23 Mar 2022 14:53:30 +0100] Univention builddaemon <buildd@univention.de>: * UCS auto build. The following patches have been applied to the original source package 05-autostart-setting 10-apache2-reload 20-no-proxy + +2.4.25-3+deb9u13 [Fri, 18 Mar 2022 13:54:25 +0100] Emilio Pozuelo Monfort <pochu@debian.org>: + + * Non-maintainer upload by the LTS team. + * CVE-2022-22719: denial of service in mod_lua via crafted request body. + * CVE-2022-22720: HTTP request smuggling. + * CVE-2022-22721: integer overflow leading to buffer overflow write. + * CVE-2022-23943: heap memory overwrite via crafted data in mod_sed. 2.4.25-3+deb9u12 [Tue, 01 Feb 2022 19:18:01 +0100] Anton Gladky <gladk@debian.org>: <http://piuparts.knut.univention.de/4.4-8/#6405147404746335686>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] a110da2d3a Bug #54580: apache2 2.4.25-3+deb9u13A~4.4.9.202203231446 doc/errata/staging/apache2.yaml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x1209>