FlawAtlas
Search the atlas
SUSE-SU-2021:3335-1 Not scored

Security update for apache2

This update for apache2 fixes the following issues: - CVE-2021-40438: Fixed a SRF via a crafted request uri-path. (bsc#1190703) - CVE-2021-36160: Fixed an out-of-bounds read via a crafted request uri-path. (bsc#1190702) - CVE-2021-39275: Fixed an out-of-bounds write in ap_escape_quotes() via malicious input. (bsc#1190666) - CVE-2021-34798: Fixed a NULL pointer dereference via malformed requests. (bsc#1190669) - CVE-2021-33193: Fixed request splitting via HTTP/2 method injection and mod_proxy. (bsc#1189387)

Exploit probability Not scored
Published October 12, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 6 apache2
SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS apache2
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS apache2
SUSE:Linux Enterprise High Performance Computing 15-ESPOS apache2
SUSE:Linux Enterprise High Performance Computing 15-LTSS apache2
SUSE:Linux Enterprise Server 15 SP1-BCL apache2
SUSE:Linux Enterprise Server 15 SP1-LTSS apache2
SUSE:Linux Enterprise Server 15-LTSS apache2
SUSE:Linux Enterprise Server for SAP Applications 15 apache2
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 apache2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2021:3335-1

This update for apache2 fixes the following issues: - CVE-2021-40438: Fixed a SRF via a crafted request uri-path. (bsc#1190703) - CVE-2021-36160: Fixed an out-of-bounds read via a crafted request uri-path. (bsc#1190702) - CVE-2021-39275: Fixed an out-of-bounds write in ap_escape_quotes() via malicious input. (bsc#1190666) - CVE-2021-34798: Fixed a NULL pointer dereference via malformed requests. (bsc#1190669) - CVE-2021-33193: Fixed request splitting via HTTP/2 method injection and mod_proxy. (bsc#1189387)

View original source

05 / REFERENCES

Further evidence