Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Debian DSA-4757-1: Apache2 Receives Important Security Upgrade

debian
Calendar Grey August 31, 2020
Debian Logo
Debian's DSA-4757-1 warns of serious vulnerabilities in the apache2 package, urging users to upgrade to ensure better security and stability for their systems
Several vulnerabilities have been found in the Apache HTTPD server

Summary

CVE-2020-1927

Fabrice Perez reported that certain mod_rewrite configurations are
prone to an open redirect.

CVE-2020-1934

Chamal De Silva discovered that the mod_proxy_ftp module uses
uninitialized memory when proxying to a malicious FTP backend.

CVE-2020-9490

Felix Wilhelm discovered that a specially crafted value for the
'Cache-Digest' header in a HTTP/2 request could cause a crash when
the server actually tries to HTTP/2 PUSH a resource afterwards.

CVE-2020-11984

Felix Wilhelm reported a buffer overflow flaw in the mod_proxy_uwsgi
module which could result in information disclosure or potentially
remote code execution.

CVE-2020-11993

Felix Wilhelm reported that when trace/debug was enabled for the
HTTP/2 module certain traffic edge patterns can cause logging
statements on the wrong connection, causing concurrent use of
memory pools.

For the stable distribution (buster), these problems have been fixed in
version 2.4.38-3+deb10u4.

We recommend tha...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: apache2
CVE ID: CVE-2020-1927 CVE-2020-1934 CVE-2020-9490 CVE-2020-11984

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here