=========================================================================Ubuntu Security Notice USN-4558-1
September 30, 2020

libapreq2 vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

libapreq2 could be made to crash if it received specially crafted network
traffic.

Software Description:
- libapreq2: a safe, standards-compliant, high-performance library used for
parsing HTTP cookies, query-strings and POST data

Details:

It was discovered that libapreq2 did not properly sanitize the Content-Type
field in certain, crafted HTTP requests. An attacker could use this
vulnerability to cause libapreq2 to crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  libapache2-mod-apreq2           2.13-7~deb10u1build0.18.04.1
  libapache2-request-perl         2.13-7~deb10u1build0.18.04.1
  libapreq2-3                     2.13-7~deb10u1build0.18.04.1
  libapreq2-dev                   2.13-7~deb10u1build0.18.04.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4558-1
  CVE-2019-12412

Package Information:
  https://launchpad.net/ubuntu/+source/libapreq2/2.13-7~deb10u1build0.18.04.1

-- 
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

Ubuntu 4558-1: libapreq2 vulnerabilities

September 30, 2020
libapreq2 could be made to crash if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libapache2-mod-apreq2 2.13-7~deb10u1build0.18.04.1 libapache2-request-perl 2.13-7~deb10u1build0.18.04.1 libapreq2-3 2.13-7~deb10u1build0.18.04.1 libapreq2-dev 2.13-7~deb10u1build0.18.04.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4558-1

CVE-2019-12412

Severity
September 30, 2020

Package Information

https://launchpad.net/ubuntu/+source/libapreq2/2.13-7~deb10u1build0.18.04.1 -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

Related News