The package yaws before version 2.0.8-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure. . Arch Linux Security Advisory ASA-202009-14 ========================================= Severity: High Date : 2020-09-26 CVE-ID : CVE-2020-12872 CVE-2020-24379 CVE-2020-24916 Package : yaws Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1228 Summary ====== The package yaws before version 2.0.8-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure. Resolution ========= Upgrade to 2.0.8-1. # pacman -Syu "yaws> =2.0.8-1" The problems have been fixed upstream in version 2.0.8. Workaround ========= None. Description ========== - CVE-2020-12872 (information disclosure) yaws_config.erl in Yaws through 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks. - CVE-2020-24379 (information disclosure) WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. - CVE-2020-24916 (arbitrary command execution) CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection. Impact ===== A remote attacker might be able to execute arbitrary commands, downgrade TLS ciphers, or load foreign entities via craftedcontent. References ========= https://github.com/erlyaws/yaws/releases/tag/yaws-2.0.8 https://vulnbe.github.io/post/yaws-xxe-and-shell-injections/ https://sweet32.info/ https://medium.com/@charlielabs101/cve-2020-12872-df315411aa70 https://packetstorm.news/tos/aHR0cHM6Ly9wYWNrZXRzdG9ybS5uZXdzL2ZpbGVzL2lkLzE1OTEwNiAxNzM0NDg2NjIyIDY0MTE5NWMwNmJmMWU3MDdiYTYzYzIzNjE1NGQ1MmNlMWEyZWFiMjUzZjBlYTBjNjBkMGU0ODdmMDYyN2QwZTk= https://github.com/erlyaws/yaws/commit/05a06345012598f5da55dbb4d041c8dc26e88e6c https://github.com/vulnbe/poc-yaws-dav-xxe https://github.com/erlyaws/yaws/commit/799b3b526d15b7a9bc43ae97165aeb085f18fac1 https://github.com/vulnbe/poc-yaws-cgi-shell-injection https://security.archlinux.org/CVE-2020-12872 https://security.archlinux.org/CVE-2020-24379 https://security.archlinux.org/CVE-2020-24916 . The Arch Linux Security Bulletin regarding yaws draws attention to critical vulnerabilities, such as the potential for unauthorized remote command execution and sensitive information exposure.. yaws security, Arch Linux advisory, command execution risk, information disclosure issue. . LinuxSecurity.com Team
Two issues have been found in yaws, a high performance HTTP 1.1 webserver written in Erlang. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2384-1
* Yaws ver. 2.0.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-aa7f37cd4d 2019-04-14 00:01:14.812568 --------------------------------------------------------------------------------Name : yaws Product : Fedora 30 Version : 2.0.6 Release : 1.fc30 URL : Summary : Web server for dynamic content written in Erlang Description : HTTP 1.0 and HTTP 1.1 web server capable of both static content page delivery and dynamic content generation using embedded Erlang code in the HTML pages. It provides virtual hosting capabilities and implements HTTP tracing and other debugging functionality such as interactive interpreter environment. Performance can be boosted with built-in support for RAM caching and streaming capabilities of dynamically generated content. Among security features are SSL and support for WWW-Authenticated pages. --------------------------------------------------------------------------------Update Information: * Yaws ver. 2.0.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1606767 - yaws: FTBFS in Fedora rawhide https://bugzilla.redhat.com/show_bug.cgi?id=1606767 [ 2 ] Bug #1357922 - CVE-2016-1000108 yaws: sets environmental variable based on user supplied Proxy request header [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1357922 [ 3 ] Bug #1676256 - yaws: FTBFS in Fedora rawhide/f30 https://bugzilla.redhat.com/show_bug.cgi?id=1676256 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-aa7f37cd4d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that yaws, a high performance HTTP 1.1 webserver, is prone to a denial of service attack via a request with a large HTTP header. . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1740-1
Get the latest Linux and open source security news straight to your inbox.