Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 594
Alerts This Week
Warning Icon 1 594

Ubuntu 22.10: USN-5942-1 Moderate: Apache HTTP Server Security Flaws

ubuntu
Calendar Grey March 9, 2023
Scroller Ubuntu
Numerous vulnerabilities identified in the Apache HTTP Server across different Ubuntu releases have been addressed with a comprehensive set of update guidelines.
Several security issues were fixed in Apache HTTP Server.

Summary

Several security issues were fixed in Apache HTTP Server.

Software Description:

- apache2: Apache HTTP server

Details:

Lars Krapf discovered that the Apache HTTP Server mod_proxy module

incorrectly handled certain configurations. A remote attacker could

possibly use this issue to perform an HTTP Request Smuggling attack.

(CVE-2023-25690)

Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server

mod_proxy_uwsgi module incorrectly handled certain special characters. A

remote attacker could possibly use this issue to perform an HTTP Request

Smuggling attack. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04

LTS, and Ubuntu 22.10. (CVE-2023-27522)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.10:
   apache2                         2.4.54-2ubuntu1.2

Ubuntu 22.04 LTS:
   apache2                         2.4.52-1ubuntu4.4

Ubuntu 20.04 LTS:
   apache2                         2.4.41-4ubuntu3.14

Ubuntu 18.04 LTS:
   apache2                         2.4.29-1ubuntu4.27

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5942-1

CVE-2023-25690, CVE-2023-27522

March 09, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.