{"id":102701,"date":"2021-12-22T09:36:38","date_gmt":"2021-12-22T07:36:38","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua"},"modified":"2021-12-22T09:36:38","modified_gmt":"2021-12-22T07:36:38","slug":"reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua","title":{"rendered":"Release of Apache HTTP Server 2.4.52 addresses buffer overflow in mod_lua","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>The release of Apache HTTP Server 2.4.52 has been published, featuring 25 changes and addressing 2 vulnerabilities:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2021-44790 \u2014 Buffer overflow in mod_lua, manifested when parsing multipart requests. The vulnerability affects configurations where Lua scripts call the r:parsebody() function to parse the request body, allowing an attacker to achieve buffer overflow by sending a specially crafted request. No exploitation has been observed yet, but the issue could potentially lead to code execution on <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/dts-newyork\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2693\">server<\/a>.\n<li class=\"l\"> CVE-2021-44224 \u2014 SSRF vulnerability (Server Side Request Forgery) in mod_proxy, allowing configurations with the 'ProxyRequests on' setting to redirect a request with a specially crafted URI to another handler on the same server, which accepts connections through Unix Domain Socket. This issue can also be exploited to cause crashes by creating conditions for dereferencing a null pointer. The problem affects Apache httpd versions starting from 2.4.7.    <\/ul>\n<p>The most notable changes not related to security:   <\/p>\n<ul>\n<li class=\"l\"> Support for building with OpenSSL 3 library has been added to mod_ssl.\n<li class=\"l\"> Improved detection of the OpenSSL library in autoconf scripts.\n<li class=\"l\"> In mod_proxy for tunneling protocols, it is now possible to disable half-close TCP connection redirection by setting the 'SetEnv proxy-nohalfclose' parameter.\n<li class=\"l\"> Additional checks have been added to ensure that URIs not meant for proxying contain an http\/https scheme, while those meant for proxying include a hostname.\n<li class=\"l\"> In mod_proxy_connect and mod_proxy, changing the status code after it has been sent to the client is prohibited.\n<li class=\"l\"> When sending intermediate responses after receiving requests with the 'Expect: 100-Continue' header, it is ensured that the response indicates the state '100 Continue', rather than the current state of the request.\n<li class=\"l\"> Support for CalDAV extensions has been added in mod_dav, where generating properties must consider both document elements and property elements. New functions dav_validate_root_ns(), dav_find_child_ns(), dav_find_next_ns(), dav_find_attr_ns(), and dav_find_attr() have been added, which can be invoked from other modules.\n<li class=\"l\"> In mpm_event, the issue of stopping idle child processes after server load spikes has been resolved.\n<li class=\"l\"> In mod_http2, regressive changes that lead to incorrect behavior when processing MaxRequestsPerChild and MaxConnectionsPerChild limits have been fixed.\n<li class=\"l\"> The capabilities of the mod_md module, used for automating the retrieval and maintenance of certificates using the ACME (Automatic Certificate Management Environment) protocol, have been expanded:\n<ul>\n<li class=\"l\"> Support for the ACME External Account Binding (EAB) mechanism has been added, which can be enabled using the MDExternalAccountBinding directive. Values for EAB can be configured from an external JSON file, allowing authentication parameters to remain concealed in the main configuration file. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/\"   title=\"server configuration\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"997\">server configuration<\/a>.\n<li class=\"l\"> In the 'MDCertificateAuthority' directive, validation is ensured by specifying a URL parameter with http\/https or one of the predefined names ('LetsEncrypt', 'LetsEncrypt-Test', 'Buypass', and 'Buypass-Test').\n<li class=\"l\">  The MDContactEmail directive is now allowed within the  section.\n<li class=\"l\"> Several bugs have been fixed, including a memory leak that occurred during failures when loading a private key.  <\/ul>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56387\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e 25 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b 2 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2021-44790 &#8212; \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432, \u0441\u043e\u0441\u0442\u043e\u044f\u0449\u0438\u0445 \u0438\u0437 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u0447\u0430\u0441\u0442\u0435\u0439 (multipart). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 Lua-\u0441\u043a\u0440\u0438\u043f\u0442\u044b \u0432\u044b\u0437\u044b\u0432\u0430\u044e\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u044e r:parsebody() \u0434\u043b\u044f \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0442\u0435\u043b\u0430 \u0437\u0430\u043f\u0440\u043e\u0441\u0430, \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0431\u0443\u0444\u0435\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u0430. \u0424\u0430\u043a\u0442\u043e\u0432 \u043d\u0430\u043b\u0438\u0447\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-102701","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e 25 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b 2 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2021-44790 - \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e 25 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b 2 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2021-44790 - \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-12-22T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-12-22T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Apache HTTP Server 2.4.52 release with a fix for the buffer overflow in mod_lua | ProHoster","description":"The release of Apache HTTP Server 2.4.52 has been published, which includes 25 changes and addresses 2 vulnerabilities: CVE-2021-44790 - a buffer overflow in mod_lua that manifests during request parsing.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e 25 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b 2 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2021-44790 - \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-12-22T07:36:38+00:00","article:modified_time":"2021-12-22T07:36:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"102701","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-12-22 07:36:51","updated":"2026-02-09 21:39:49","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/102701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=102701"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/102701\/revisions"}],"predecessor-version":[{"id":159973,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/102701\/revisions\/159973"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=102701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=102701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=102701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}