FlawAtlas
Search the atlas
SUSE-SU-2021:3299-1 Not scored

Security update for apache2

This update for apache2 fixes the following issues: - CVE-2021-40438: Fixed a SRF via a crafted request uri-path. (bsc#1190703) - CVE-2021-39275: Fixed an out-of-bounds write in ap_escape_quotes() via malicious input. (bsc#1190666) - CVE-2021-34798: Fixed a NULL pointer dereference via malformed requests. (bsc#1190669)

Exploit probability Not scored
Published October 6, 2021
Required by Not available
Last source change May 2, 2025

02 / AFFECTED SOFTWARE

Affected packages

SUSE:HPE Helion OpenStack 8 apache2
SUSE:Linux Enterprise Server 12 SP2-BCL apache2
SUSE:Linux Enterprise Server 12 SP3-BCL apache2
SUSE:Linux Enterprise Server 12 SP3-LTSS apache2
SUSE:Linux Enterprise Server 12 SP4-LTSS apache2
SUSE:Linux Enterprise Server 12 SP5 apache2
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 apache2
SUSE:Linux Enterprise Server for SAP Applications 12 SP4 apache2
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 apache2
SUSE:Linux Enterprise Software Development Kit 12 SP5 apache2
SUSE:OpenStack Cloud 8 apache2
SUSE:OpenStack Cloud 9 apache2
SUSE:OpenStack Cloud Crowbar 8 apache2
SUSE:OpenStack Cloud Crowbar 9 apache2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2021:3299-1

This update for apache2 fixes the following issues: - CVE-2021-40438: Fixed a SRF via a crafted request uri-path. (bsc#1190703) - CVE-2021-39275: Fixed an out-of-bounds write in ap_escape_quotes() via malicious input. (bsc#1190666) - CVE-2021-34798: Fixed a NULL pointer dereference via malformed requests. (bsc#1190669)

View original source

05 / REFERENCES

Further evidence