Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-36160

Опубликовано: 16 сент. 2021
Источник: debian

Описание

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.49-1package
apache2not-affectedstretchpackage
uwsgiunfixedpackage

Примечания

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2021-36160

  • https://github.com/apache/httpd/commit/b364cad72b48dd40fbc2850e525b845406520f0b

  • uwsgi since 2.0.15-11 drops building the libapache2-mod-proxy-uwsgi{,-dbg}

  • packages which are provided by src:apache2 itself.

  • Regression report: https://bz.apache.org/bugzilla/show_bug.cgi?id=65616

  • Regression patch: https://github.com/apache/httpd/commit/8966e290a6e947fad0289bf4e243b0b552e13726 (2.4.x)

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).

CVSS3: 7.5
redhat
почти 4 года назад

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).

CVSS3: 7.5
nvd
почти 4 года назад

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
github
около 3 лет назад

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).