2020年8月16日 星期日

[USN-4458-1] Apache HTTP Server vulnerabilities

 ---------- Forwarded message ---------

From: Marc Deslauriers <marc.deslauriers@canonical.com>

Date: Aug 13, 2020 11:20PM

Fabrice Perez discovered that the Apache mod_rewrite module incorrectly

handled certain redirects. A remote attacker could possibly use this issue

to perform redirects to an unexpected URL. (CVE-2020-1927)

Chamal De Silva discovered that the Apache mod_proxy_ftp module incorrectly

handled memory when proxying to a malicious FTP server. A remote attacker

could possibly use this issue to obtain sensitive information.

(CVE-2020-1934)

Felix Wilhelm discovered that the HTTP/2 implementation in Apache did not

properly handle certain Cache-Digest headers. A remote attacker could

possibly use this issue to cause Apache to crash, resulting in a denial of

service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.

(CVE-2020-9490)

Felix Wilhelm discovered that the Apache mod_proxy_uwsgi module incorrectly

handled large headers. A remote attacker could use this issue to obtain

sensitive information or possibly execute arbitrary code. This issue only

affected Ubuntu 20.04 LTS. (CVE-2020-11984)

Felix Wilhelm discovered that the HTTP/2 implementation in Apache did not

properly handle certain logging statements. A remote attacker could

possibly use this issue to cause Apache to crash, resulting in a denial of

service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.

(CVE-2020-11993)

References:

  https://usn.ubuntu.com/4458-1

  CVE-2020-11984, CVE-2020-11993, CVE-2020-1927, CVE-2020-1934,

  CVE-2020-9490

沒有留言:

張貼留言