Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Ubuntu 16.04 ESM USN-5520-2: HTTP Request Smuggling Risk Details

Ubuntu Large Esm H500
HTTP-Daemon could allow HTTP Request Smuggling attacks.
=========================================================================Ubuntu Security Notice USN-5520-2
July 18, 2022

libhttp-daemon-perl vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

HTTP-Daemon could allow HTTP Request Smuggling attacks.

Software Description:
- libhttp-daemon-perl: simple http server class

Details:

USN-5520-1 fixed a vulnerability in HTTP-Daemon. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

 It was discovered that HTTP-Daemon incorrectly handled certain crafted
 requests. A remote attacker could possibly use this issue to perform an
 HTTP Request Smuggling attack.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
  libhttp-daemon-perl             6.01-1ubuntu0.16.04~esm1

Ubuntu 14.04 ESM:
  libhttp-daemon-perl             6.01-1ubuntu0.14.04~esm1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5520-2
  https://ubuntu.com/security/notices/USN-5520-1
  CVE-2022-31081

Ubuntu 16.04 ESM USN-5520-2: HTTP Request Smuggling Risk Details

ubuntu
Calendar Grey July 18, 2022
Dist Ubuntu Esm H88
Ubuntu Security Notice USN-5530-1 reports a vulnerability in the HTTP-Daemon, which may result in HTTP Request Smuggling exploits. Ensure your system is patched!
HTTP-Daemon could allow HTTP Request Smuggling attacks.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libhttp-daemon-perl 6.01-1ubuntu0.16.04~esm1 Ubuntu 14.04 ESM: libhttp-daemon-perl 6.01-1ubuntu0.14.04~esm1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5520-2

https://ubuntu.com/security/notices/USN-5520-1

CVE-2022-31081

Severity
critical
Lowest
Low
Medium
High
Critical

July 18, 2022

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here