Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE 15-SP3: 2022:0091-1 Important: Apache2 Buffer Overflow and SSRF Fix

suse
Calendar Grey January 17, 2022
Dist Suse Esm H88
SUSE Security Patch for nginx tackles urgent vulnerabilities impacting various platforms and functionalities.
An update that fixes two vulnerabilities, contains two features is now available

Summary

This update for apache2 fixes the following issues: Apache2 was updated to the current stable version 2.4.51 (jsc#SLE-22733 jsc#SLE-22849) It fixes all CVEs and selected bugs represented by patches found between 2.4.23 and 2.4.51. See https://downloads.apache.org/httpd/CHANGES_2.4 for a complete change log. Also fixed: - CVE-2021-44224: Fixed NULL dereference or SSRF in forward proxy configurations (bsc#1193943) - CVE-2021-44790: Fixed buffer overflow when parsing multipart content in mod_lua (bsc#1193942) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP3:

References

#1193942 #1193943 SLE-22733 SLE-22849

Cross- CVE-2021-44224 CVE-2021-44790

CVSS scores:

CVE-2021-44224 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2021-44790 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Module for Server Applications 15-SP3

SUSE Linux Enterprise Module for Server Applications 15-SP2

SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3

SUSE Linux Enterprise Module for Basesystem 15-SP3

SUSE Linux Enterprise Module for Basesystem 15-SP2

https://www.suse.com/security/cve/CVE-2021-44224.html

https://www.suse.com/security/cve/CVE-2021-44790.html

https://bugzilla.suse.com/1193942

https://bugzilla.suse.com/1193943

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0091-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here