Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia: 2022-0105 Moderate: Apache Out-Of-Bounds Memory Issue

mageia
Calendar Grey March 21, 2022
Dist Mageia Esm H88
Enhanced Apache components tackle severe out-of-bounds vulnerability, mitigating various security risks in Mageia 8.
SECURITY: CVE-2022-23943: mod_sed: Read/write beyond bounds

Summary

SECURITY: CVE-2022-23943: mod_sed: Read/write beyond bounds. Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. Credits: Ronald Crane (Zippenhop LLC)
SECURITY: CVE-2022-22721: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. Credits: Anonymous working with Trend Micro Zero Day Initiative
SECURITY: CVE-2022-22720: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling Credits: James Kettle
SECURITY: CVE-2022-22719: mod_lua Use of uninitialized value of in r:parsebody A carefully crafted r...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=30170

- https://downloads.apache.org/httpd/Announcement2.4.html

- - https://httpd.apache.org/security/vulnerabilities_24.html

- https://www.cve.org/CVERecord?id=CVE-2022-23943

- https://www.cve.org/CVERecord?id=CVE-2022-22721

- https://www.cve.org/CVERecord?id=CVE-2022-22720

- https://www.cve.org/CVERecord?id=CVE-2022-22719

Resolution

SRPMS

- 8/core/apache-2.4.53-1.mga8

Publication date: 21 Mar 2022
URL: https://advisories.mageia.org/MGASA-2022-0105.html
Type: security
CVE: CVE-2022-23943, CVE-2022-22721, CVE-2022-22720, CVE-2022-22719

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here