You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa apache2

Sigurnosni nedostaci programskog paketa apache2

  • Detalji os-a: WN7
  • Važnost: URG
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3937-1
April 04, 2019

apache2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.10
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the Apache HTTP Server.

Software Description:
– apache2: Apache HTTP server

Details:

Charles Fol discovered that the Apache HTTP Server incorrectly handled the
scoreboard shared memory area. A remote attacker able to upload and run
scripts could possibly use this issue to execute arbitrary code with root
privileges. (CVE-2019-0211)

It was discovered that the Apache HTTP Server HTTP/2 module incorrectly
handled certain requests. A remote attacker could possibly use this issue
to cause the server to consume resources, leading to a denial of service.
This issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10.
(CVE-2018-17189)

It was discovered that the Apache HTTP Server incorrectly handled session
expiry times. When used with mod_session_cookie, this may result in the
session expiry time to be ignored, contrary to expectations.
(CVE-2018-17199)

Craig Young discovered that the Apache HTTP Server HTTP/2 module
incorrectly handled certain requests. A remote attacker could possibly use
this issue to cause the server to process requests incorrectly. This issue
only affected Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2019-0196)

Simon Kappel discovered that the Apache HTTP Server mod_auth_digest module
incorrectly handled threads. A remote attacker with valid credentials could
possibly use this issue to authenticate using another username, bypassing
access control restrictions. (CVE-2019-0217)

Bernhard Lorenz discovered that the Apache HTTP Server was inconsistent
when processing requests containing multiple consecutive slashes. This
could lead to directives such as LocationMatch and RewriteRule to perform
contrary to expectations. (CVE-2019-0220)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.10:
apache2-bin 2.4.34-1ubuntu2.1

Ubuntu 18.04 LTS:
apache2-bin 2.4.29-1ubuntu4.6

Ubuntu 16.04 LTS:
apache2-bin 2.4.18-2ubuntu3.10

Ubuntu 14.04 LTS:
apache2-bin 2.4.7-1ubuntu4.22

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3937-1
CVE-2018-17189, CVE-2018-17199, CVE-2019-0196, CVE-2019-0211,
CVE-2019-0217, CVE-2019-0220

Package Information:
https://launchpad.net/ubuntu/+source/apache2/2.4.34-1ubuntu2.1
https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.6
https://launchpad.net/ubuntu/+source/apache2/2.4.18-2ubuntu3.10
https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.22

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlymJqAACgkQZWnYVadE
vpPLJRAAt5oe8+biQRHvQer8vyOmMxIOP3qeMT6bgJrYC74mVL1OPOVMEVdRd3KU
txN0RULTNzzKgfCA6g9whEa1JcAgcu/rsGhpHvmxDyUH4ffsNu5XCmC0lmCXU0cj
Sy+8EMtjVKc4+YwjoIFORw9glKERYFlov6uFf8vd7YeIrqjOZT+TNZwavYi8ofr8
tUH9yk/gjspK6DUQHlLU1SACIOlyzzMeJZkJPWROFnW4/EXtRA48wZyTjqg49nI0
KvKb4xfwBU/rOPH98lZOlOTWw0L8wO09Smq1zzb2JXs9vbT6+yPgHM4JYvmjTBt1
0AsHd2yVWwsHJ0HvOfdX7MSoCGgajdGSnyy8rZ16XDpAvmjvZL7TZDmmxDW2a4VE
7y/j98KlSkorHTh0zAbwb2GzeIPTCwkwj975cAqHBwRMq5JcfIN9w6J3m7K5UXcB
kY+zm3/koL6X+EebTOFdag2OK8hTIiRlbRlrSFDd3w4ssuLljZA/RZHgyjQL3ROm
skNqOHikDP48rwFn84kIvYUj3JIsqBvXXOPXsPlIV55sU/HQLgQ6X5CfKV25L9yq
EY0mrVYwbj5BWLPLfUwM7TsVWSE8gmMRJrjDvPaeO4cS0xytFZimABK2gjWpgQc3
mD9CDVlwcHizpdbVj6EJQGgcVRgSm/46vHx15yBWTiFSvbp0dJ8=
=qPTm
—–END PGP SIGNATURE—–

AutorToni Vugdelija
Cert idNCERT-REF-2019-04-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa pdns

Otkriven je sigurnosni nedostatak u programskom paketu pdns za operacijski sustav openSUSE. Otkriveni nedostatak potencijalnim napadačima omogućuje izazivanje DoS stanja,...

Close