Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: 2021-0439 Moderate: Apache Cache Poisoning and Request Splitting

mageia
Calendar Grey September 23, 2021
Dist Mageia Esm H88
Patch rollout for Mageia addressing Apache module flaws, rectifying issues related to request smuggling and cache contamination threats.
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning

Summary

A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. (CVE-2021-33193)
Malformed requests may cause the server to dereference a NULL pointer. (CVE-2021-34798)
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). (CVE-2021-36160)
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. (CVE-2021-39275)
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. (CVE-2021-40438)

References

- https://bugs.mageia.org/show_bug.cgi?id=29466

- https://downloads.apache.org/httpd/Announcement2.4.html

- - https://httpd.apache.org/security/vulnerabilities_24.html

- https://www.cve.org/CVERecord?id=CVE-2021-33193

- https://www.cve.org/CVERecord?id=CVE-2021-34798

- https://www.cve.org/CVERecord?id=CVE-2021-36160

- https://www.cve.org/CVERecord?id=CVE-2021-39275

- https://www.cve.org/CVERecord?id=CVE-2021-40438

Resolution

SRPMS

- 8/core/apache-2.4.49-1.mga8

Publication date: 23 Sep 2021
URL: https://advisories.mageia.org/MGASA-2021-0439.html
Type: security
CVE: CVE-2021-33193, CVE-2021-34798, CVE-2021-36160, CVE-2021-39275, CVE-2021-40438

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here