Release of Apache HTTP Server 2.4.49 with vulnerability fixes

The release of HTTP Server Apache 2.4.49 has been published, featuring 27 changes and addressing 5 vulnerabilities:

  • CVE-2021-33193 — vulnerability of mod_http2 to a new variant of the 'HTTP Request Smuggling' attack, which allows injection into the content of other users' requests via specially crafted client requests sent through mod_proxy (for instance, it can lead to the insertion of malicious JavaScript code into another user's session).
  • CVE-2021-40438 — SSRF vulnerability (Server Side Request Forgery) in mod_proxy, enabling attackers to redirect requests to a server of their choice by sending a specially crafted uri-path request.
  • CVE-2021-39275 — buffer overflow in the ap_escape_quotes function. The vulnerability is marked as low-risk since all standard modules do not pass external data to this function. However, it is theoretically possible that there exist third-party modules that could enable an attack.
  • CVE-2021-36160 — out-of-bounds read in the mod_proxy_uwsgi module, leading to a crash.
  • CVE-2021-34798 — dereferencing a null pointer, causing the process to crash when handling specially crafted requests.

The most notable changes not related to security:

  • A considerable number of internal changes have been made in mod_ssl. The settings 'ssl_engine_set', 'ssl_engine_disable', and 'ssl_proxy_enable' have been moved from mod_ssl to the core. The option to use alternative modules for securing connections through mod_proxy has been provided. SSL-modules for protecting connections through mod_proxy. The logging of closed keys has been added, which can be used in Wireshark for analyzing encrypted traffic.
  • In mod_proxy, the parsing of paths with unix socket, sent in the URL 'proxy:', has been accelerated.
  • The capabilities of the mod_md module, used for automating the acquisition and maintenance of certificates via the ACME (Automatic Certificate Management Environment) protocol, have been expanded. Quoting of domains in is allowed, and support for tls-alpn-01 has been provided, not tied to virtual hosts. domain namesA new StrictHostCheck parameter has been added, prohibiting the specification of unconfigured host names among the arguments in the 'allow' list.
  • Vulnerability in Travis CI leading to leakage of keys from public repositories

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster