[CLSA-2023:1689009164] Fix CVE(s): CVE-2022-29404
Type:
security
Severity:
Important
Release date:
2023-07-10 17:12:49 UTC
Description:
* SECURITY UPDATE: mod_lua may denial of service in r:parsebody(0) - debian/patches/CVE-2022-29404.patch: use a liberal default limit for LimitRequestBody of 1GB to prevent a denial of service caused by a malicious lua script request - CVE-2022-29404
Updated packages:
  • apache2_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb
    sha:7dd68f21e174f645f8a536679db934cdcfe7bbea
  • apache2-bin_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb
    sha:cfb4ff76f0fc281f81983e03c3cdff71ca68e7b7
  • apache2-data_2.4.18-2ubuntu3.17+tuxcare.els11_all.deb
    sha:2333df718ee9d59953a260a796fd3145c2326325
  • apache2-dev_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb
    sha:9c5d485d5e9161a2bd3ee148c04e7d0e88a42734
  • apache2-doc_2.4.18-2ubuntu3.17+tuxcare.els11_all.deb
    sha:90d3c1226ca664fecfdc6162f0587a37f333229b
  • apache2-suexec-custom_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb
    sha:26b9d0a5ac3afdc0cd333610fab3f23f5f7487de
  • apache2-suexec-pristine_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb
    sha:8bdb225a3eec608637922d4097002a716b102113
  • apache2-utils_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb
    sha:8a4b2713a335fbd9ab8ab32338f3e3a18a25a3bb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.