Release of Apache 2.4.41 with vulnerability fixes

Published Release of the Apache HTTP server 2.4.41 (the 2.4.40 release was skipped), which features 23 changes and fixes 6 vulnerabilities:

  • CVE-2019-10081 — an issue in mod_http2 that can lead to memory corruption when sending push requests at a very early stage. When using the "H2PushResource" configuration, it is possible to overwrite memory areas in the request handling pool, but the issue is limited to crashes, as the data written is not based on information obtained from the client;
  • CVE-2019-9517 — exposure to a recently announced DoS vulnerability in HTTP/2 implementations.
    An attacker can exhaust available process memory and create a high CPU load by opening an HTTP/2 sliding window to send data from the server without limits, while keeping the TCP window closed, which prevents actual data from being written to the socket;
  • CVE-2019-10098 — an issue in mod_rewrite that allows the server to forward requests to other resources (open redirect). Certain mod_rewrite configurations can lead to forwarding the user to another link encoded with a newline character inside the parameter used in the existing redirect. To block the issue, the PCRE_DOTALL flag can be used in RegexDefaultOptions, which is now set by default;
  • CVE-2019-10092 — the potential for cross-site scripting on error pages generated by mod_proxy. On these pages, the link is filled with the URL obtained from the request, where an attacker can inject arbitrary HTML code through character escaping;
  • CVE-2019-10097 — stack overflow and NULL pointer dereference in mod_remoteip, exploited through manipulation of the PROXY protocol header. The attack can only be carried out from the proxy server settings being used, not through the client request;
  • CVE-2019-10082 — a vulnerability in mod_http2 that enables reading content from an already freed memory area (read-after-free) at the time of connection termination.

The most notable changes not related to security:

  • In mod_proxy_balancer, enhanced protection against XSS/XSRF attacks from trusted nodes;
  • In mod_session, added the SessionExpiryUpdateInterval setting to define the cookie/session expiration update interval;
  • Conducted cleanup of error pages to prevent displaying request information on those pages;
  • The mod_http2 module now takes the value of the 'LimitRequestFieldSize' parameter into account, which previously only applied to the validation of HTTP/1.1 header fields;
  • Configuration creation of mod_proxy_hcheck has been ensured when used in BalancerMember;
  • Memory consumption in mod_dav has been reduced when using the PROPFIND command on a large collection;
  • Issues regarding the specification of certificate and SSL settings within the Proxy block have been resolved in mod_proxy and mod_ssl;
  • SSLProxyCheckPeer* settings are now allowed to be applied for all proxy modules in mod_proxy;
  • The capabilities of the module mod_md, developed by the Let’s Encrypt project for automating the obtaining and maintenance of certificates using the ACME (Automatic Certificate Management Environment) protocol:
    • The second version of the protocol has been added, ACMEv2, which is now applied by default and use uses empty POST requests instead of GET.
    • Support for checking based on the TLS-ALPN-01 extension (RFC 7301, Application-Layer Protocol Negotiation), which is used in HTTP/2, has been added.
    • Support for the 'tls-sni-01' check method has been discontinued (due to a vulnerability).
    • Commands for setting up and breaking the check method 'dns-01' have been added.
    • Support added masks in certificates when DNS-based checking ('dns-01') is enabled.
    • The 'md-status' handler and the certificate status page 'https://domain/.httpd/certificate-status' have been implemented.
    • The 'MDCertificateFile' and 'MDCertificateKeyFile' directives have been added for configuring domain parameters through static files (without support for auto-renewal).
    • The 'MDMessageCmd' directive has been added for calling external commands upon the events 'renewed', 'expiring', or 'errored'.
    • The 'MDWarnWindow' directive has been added for configuring a warning message about the expiration of the certificate;

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster