Bug 41826

Summary: apache2: Multiple issues (4.1)
Product: UCS Reporter: Arvid Requate <requate>
Component: Security updatesAssignee: Philipp Hahn <hahn>
Status: CLOSED FIXED QA Contact: Arvid Requate <requate>
Severity: normal    
Priority: P3 CC: best, gohmann
Version: UCS 4.1Flags: requate: Patch_Available+
Target Milestone: UCS 4.1-3-errata   
Hardware: Other   
OS: Linux   
What kind of report is it?: Security Issue What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?:
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional): External feedback, Security
Max CVSS v3 score:
Bug Depends on:    
Bug Blocks: 41827, 41828, 43770    

Description Arvid Requate univentionstaff 2016-07-20 18:28:53 CEST
Upstream Debian package version 2.2.22-13+deb7u7 fixes the following issue:

* The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httproxy" issue.  NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability. (CVE-2016-5387)

CVSS v2 base score 5 (AV:N/AC:L/Au:N/C:N/I:P/A:N)

Please note that the current package has been rebuilt with the additional Debian patches from deb7u6 (Bug #40929)
Comment 1 Florian Best univentionstaff 2016-08-23 18:34:03 CEST
Ticket#2016082321000687
Comment 2 Philipp Hahn univentionstaff 2016-09-28 10:44:37 CEST
repo_admin.py -U -r 4.1 -s errata4.1-3 -d wheezy -p apache2

r16746

Package: apache2
Version: 2.2.22-13.101.201609281005
Branch: ucs_4.1-0
Scope: errata4.1-3

r72849 | Bug #42491,Bug #32018 home: Fix umount
 apache2.yaml
Comment 3 Arvid Requate univentionstaff 2016-10-11 17:16:36 CEST
Verified:
* Package imported and built with existing patches
* OK: ucs-test -s apache -E dangerous
* Advisory Ok
Comment 4 Janek Walkenhorst univentionstaff 2016-10-12 13:06:46 CEST
<http://errata.software-univention.de/ucs/4.1/289.html>