Moderate: httpd security, bug fix, and enhancement update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. The following packages have been upgraded to a later upstream version: httpd (2.4.53). (BZ#2079939) Security Fix(es): * httpd: mod_sed: Read/write beyond bounds (CVE-2022-23943) * httpd: mod_lua: Use of uninitialized value of in r:parsebody (CVE-2022-22719) * httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody (CVE-2022-22721) * httpd: mod_proxy_ajp: Possible request smuggling (CVE-2022-26377) * httpd: mod_lua: DoS in r:parsebody (CVE-2022-29404) * httpd: mod_sed: DoS vulnerability (CVE-2022-30522) * httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism (CVE-2022-31813) * httpd: Out-of-bounds read via ap_rwrite() (CVE-2022-28614) * httpd: Out-of-bounds read in ap_strcmp_match() (CVE-2022-28615) * httpd: mod_lua: Information disclosure with websockets (CVE-2022-30556) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. The following packages have been upgraded to a later upstream version: httpd (2.4.53). (BZ#2079939) Security Fix(es): * httpd: mod_sed: Read/write beyond bounds (CVE-2022-23943) * httpd: mod_lua: Use of uninitialized value of in r:parsebody (CVE-2022-22719) * httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody (CVE-2022-22721) * httpd: mod_proxy_ajp: Possible request smuggling (CVE-2022-26377) * httpd: mod_lua: DoS in r:parsebody (CVE-2022-29404) * httpd: mod_sed: DoS vulnerability (CVE-2022-30522) * httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism (CVE-2022-31813) * httpd: Out-of-bounds read via ap_rwrite() (CVE-2022-28614) * httpd: Out-of-bounds read in ap_strcmp_match() (CVE-2022-28615) * httpd: mod_lua: Information disclosure with websockets (CVE-2022-30556) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2022:8067
- https://access.redhat.com/security/cve/CVE-2022-22719
- https://access.redhat.com/security/cve/CVE-2022-22721
- https://access.redhat.com/security/cve/CVE-2022-23943
- https://access.redhat.com/security/cve/CVE-2022-26377
- https://access.redhat.com/security/cve/CVE-2022-28614
- https://access.redhat.com/security/cve/CVE-2022-28615
- https://access.redhat.com/security/cve/CVE-2022-29404
- https://access.redhat.com/security/cve/CVE-2022-30522
- https://access.redhat.com/security/cve/CVE-2022-30556
- https://access.redhat.com/security/cve/CVE-2022-31813
- https://bugzilla.redhat.com/2064319
- https://bugzilla.redhat.com/2064320
- https://bugzilla.redhat.com/2064322
- https://bugzilla.redhat.com/2094997
- https://bugzilla.redhat.com/2095002
- https://bugzilla.redhat.com/2095006
- https://bugzilla.redhat.com/2095012
- https://bugzilla.redhat.com/2095015
- https://bugzilla.redhat.com/2095018
- https://bugzilla.redhat.com/2095020
- https://errata.almalinux.org/9/ALSA-2022-8067.html