[CLSA-2021:1640697114] Fix CVE(s): CVE-2021-44224, CVE-2021-44970
Type:
security
Severity:
moderate
Release date:
2021-12-28 13:11:54 UTC
Description:
* SECURITY UPDATE: buffer overflow in the mod_lua multipart parser - debian/patches/CVE-2021-44970.patch: add test to prevent integer overflow in req_parsebody() - CVE-2021-44970 * SECURITY UPDATE: null pointer dereference in reverse proxy module - debian/patches/CVE-2021-44224.patch: add tests for return value of ap_proxy_de_socketfy() - CVE-2021-44224
Updated packages:
  • apache2_2.4.18-2ubuntu3.17+tuxcare.els3_amd64.deb
    sha:a9ff40cee693444642a3d39b7ca6e4d3a390f937
  • apache2-bin_2.4.18-2ubuntu3.17+tuxcare.els3_amd64.deb
    sha:2ea687734d4bac5412be28682edcc581e39f757e
  • apache2-data_2.4.18-2ubuntu3.17+tuxcare.els3_all.deb
    sha:a075a7b294aff83f975bdecf7b2935a6969db28b
  • apache2-dev_2.4.18-2ubuntu3.17+tuxcare.els3_amd64.deb
    sha:a0bfc44f7444f418cc3bf9775f0baf9b47d46dce
  • apache2-doc_2.4.18-2ubuntu3.17+tuxcare.els3_all.deb
    sha:f64792d1da9bb1de16712b36e8246291f4408a8a
  • apache2-suexec-custom_2.4.18-2ubuntu3.17+tuxcare.els3_amd64.deb
    sha:6aeb1fe6d3f01807e96805aa1dce45cf4485826d
  • apache2-suexec-pristine_2.4.18-2ubuntu3.17+tuxcare.els3_amd64.deb
    sha:0198dddeac75c7b719c319f023ceb4bf94c4e33d
  • apache2-utils_2.4.18-2ubuntu3.17+tuxcare.els3_amd64.deb
    sha:473fd2daee63de0f2cac2d34b49b0ebe700f28df
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.