You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa apache2

Sigurnosni nedostaci programskog paketa apache2

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3627-2
April 30, 2018

apache2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in the Apache HTTP Server.

Software Description:
– apache2: Apache HTTP server

Details:

USN-3627-1 fixed vulnerabilities in Apache HTTP Server. This update
provides the corresponding updates for Ubuntu 18.04 LTS.

Original advisory details:

Alex Nichols and Jakob Hirsch discovered that the Apache HTTP Server
mod_authnz_ldap module incorrectly handled missing charset encoding
headers. A remote attacker could possibly use this issue to cause the
server to crash, resulting in a denial of service. (CVE-2017-15710)
Elar Lang discovered that the Apache HTTP Server incorrectly handled
certain characters specified in <FilesMatch>. A remote attacker could
possibly use this issue to upload certain files, contrary to expectations.
(CVE-2017-15715)
It was discovered that the Apache HTTP Server mod_session module
incorrectly handled certain headers. A remote attacker could possibly use
this issue to influence session data. (CVE-2018-1283)
Robert Swiecki discovered that the Apache HTTP Server incorrectly handled
certain requests. A remote attacker could possibly use this issue to cause
the server to crash, leading to a denial of service. (CVE-2018-1301)
Robert Swiecki discovered that the Apache HTTP Server mod_cache_socache
module incorrectly handled certain headers. A remote attacker could
possibly use this issue to cause the server to crash, leading to a denial
of service. (CVE-2018-1303)
Nicolas Daniels discovered that the Apache HTTP Server incorrectly
generated the nonce when creating HTTP Digest authentication challenges.
A remote attacker could possibly use this issue to replay HTTP requests
across a cluster of servers. (CVE-2018-1312)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
apache2-bin 2.4.29-1ubuntu4.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3627-2
https://usn.ubuntu.com/usn/usn-3627-1
CVE-2017-15710, CVE-2017-15715, CVE-2018-1283, CVE-2018-1301,
CVE-2018-1303, CVE-2018-1312

Package Information:
https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.1

—–BEGIN PGP SIGNATURE—–

iQIcBAEBCgAGBQJa50uSAAoJEGVp2FWnRL6TXfYP/RS59meK5VMolndduknNPQlK
Z0u421Lg1fV5KpwYEqmO7qlmptsbelyslS2gCgkWocaGI9FPparhXA1iwbStH0F/
EmUtBk1CgLl5R1M6SVxSCrj7pOY747xg3T30x2Mut557p5ELgUPWJVkVruv0fX4f
9MVX35WeR8Ah79I2Fp0yV/LSa/kY+nf4ciHeIxugYa34h6wH9SXIAVPoovavI5U2
hXsPzSqhiI6YnPPcnqwgkP6nd+yzzZDzVgnzJQ9lqWkEhAxHXSlDtuMfYz6C1Rfc
xocEjjw4uRNHrqiXxhDFQuKEUar/zXxn0dLjcW/valfT7sVHSr8FWiwLVCAcB4RV
r9uJlscKcTW9MRPTXqejRIVbdF2yyJcnO5o9ZpAS9z6mT4wgax2jKvOD/AYC6jHt
1xpgfbruLtnDepxOZb7DacWP/mAeDqCA01+nrt+368I6CZ0SUigiLR29jb45LjBq
rV5o7t+DfzLnNRAuuYSFQkPFAIrkRVJjx/mX8UAvm+XdY4zVYld5DFfreN0DZvgy
Hgrwp1Nnpm/fKuLIIE/4Crz79p3wHY9XG8uOzqe2EfXsTJr0SE9MXikmx/RcVZRw
Bho14eYz5jDkf9WFaO7EjzfSJdxvXekGLPIckh/DRAVTGy0MPYGoZV6PUkSjrutC
I8XGn6hrukedVPO6G0bX
=pYIu
—–END PGP SIGNATURE—–

AutorVlatka Misic
Cert idNCERT-REF-2018-05-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa java-1.7.0-openjdk

Otkriveni su sigurnosni nedostaci u programskom paketu java-1.7.0-openjdk za operacijski sustav RHEL 6. Otkriveni nedostaci potencijalnim napadačima omogućuju narušavanje integriteta,...

Close