{"id":102701,"date":"2021-12-22T09:36:38","date_gmt":"2021-12-22T07:36:38","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua"},"modified":"2021-12-22T09:36:38","modified_gmt":"2021-12-22T07:36:38","slug":"reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua","title":{"rendered":"Rilascio del server HTTP Apache 2.4.52 con correzione del buffer overflow in mod_lua","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Pubblicato il rilascio del server HTTP Apache 2.4.52, che presenta 25 modifiche e risolve 2 vulnerabilit\u00e0:  <\/p>\n<ul>\n<li class=\"l\"> CVE-2021-44790 \u2014 overflow del buffer in mod_lua, che si manifesta durante l'analisi di richieste multipart. La vulnerabilit\u00e0 colpisce configurazioni in cui script Lua chiamano la funzione r:parsebody() per analizzare il corpo della richiesta, consentendo a un attaccante di causare un overflow del buffer inviando una richiesta appositamente formattata. Al momento non sono stati identificati exploit, ma potenzialmente il problema potrebbe portare all'esecuzione di codice non autorizzato. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-newyork\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2693\">server<\/a>.\n<li class=\"l\"> CVE-2021-44224 \u2014 vulnerabilit\u00e0 SSRF (Server Side Request Forgery) in mod_proxy, che consente, in configurazioni con l'impostazione 'ProxyRequests on', di reindirizzare una richiesta a un altro handler sullo stesso server che accetta connessioni tramite Unix Domain Socket. Il problema pu\u00f2 essere sfruttato anche per causare un crash creando le condizioni per dereferenziare un puntatore nullo. La problematica riguarda le versioni di Apache httpd a partire dalla versione 2.4.7.    <\/ul>\n<p>Le modifiche pi\u00f9 significative non correlate alla sicurezza:   <\/p>\n<ul>\n<li class=\"l\"> In mod_ssl \u00e8 stata aggiunta la supporto per la compilazione con la libreria OpenSSL 3.\n<li class=\"l\"> Migliorato il rilevamento della libreria OpenSSL negli script autoconf.\n<li class=\"l\"> In mod_proxy, per i protocolli di tunneling \u00e8 possibile disabilitare il reindirizzamento delle connessioni TCP semi-aperte (half-close) impostando il parametro 'SetEnv proxy-nohalfclose'.\n<li class=\"l\"> Aggiunti ulteriori controlli affinch\u00e9 gli URI non destinati al proxy contengano lo schema http\/https, mentre quelli destinati al proxy contengano il nome host.\n<li class=\"l\"> In mod_proxy_connect e mod_proxy \u00e8 vietata la modifica del codice di stato dopo che \u00e8 stato inviato al client.\n<li class=\"l\"> Quando si inviano risposte intermedie dopo aver ricevuto richieste con l'intestazione 'Expect: 100-Continue', viene indicato come risultato lo stato '100 Continue', piuttosto che lo stato attuale della richiesta.\n<li class=\"l\"> In mod_dav \u00e8 stato aggiunto supporto per estensioni CalDAV, in cui durante la generazione delle propriet\u00e0 devono essere considerati sia gli elementi del documento che gli elementi della propriet\u00e0. Sono state aggiunte nuove funzioni dav_validate_root_ns(), dav_find_child_ns(), dav_find_next_ns(), dav_find_attr_ns() e dav_find_attr(), che possono essere richiamate da altri moduli.\n<li class=\"l\"> In mpm_event \u00e8 stato risolto un problema con l'arresto dei processi figli inattivi dopo un picco di carico sul server.\n<li class=\"l\"> In mod_http2 sono state risolte modifiche regressive che causavano un comportamento errato nella gestione dei limiti MaxRequestsPerChild e MaxConnectionsPerChild.\n<li class=\"l\"> Ampliate le funzionalit\u00e0 del modulo mod_md, utilizzato per automatizzare l'ottenimento e la gestione dei certificati tramite il protocollo ACME (Automatic Certificate Management Environment):\n<ul>\n<li class=\"l\"> Aggiunta la supporto per il meccanismo ACME External Account Binding (EAB), attivabile tramite la direttiva MDExternalAccountBinding. I valori per EAB possono essere configurati da un file esterno in formato JSON, consentendo di non rivelare i parametri di autenticazione nel file principale <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/\"   title=\"configurazione del server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"997\">configurazione del server<\/a>.\n<li class=\"l\"> Nella direttiva 'MDCertificateAuthority' \u00e8 stata implementata la verifica dell'indicazione nell'URL del parametro http\/https o di uno dei nomi predefiniti ('LetsEncrypt', 'LetsEncrypt-Test', 'Buypass' e 'Buypass-Test').\n<li class=\"l\">  \u00c8 consentita la specifica della direttiva MDContactEmail all'interno della sezione .\n<li class=\"l\"> Corrette diverse anomalie, inclusa una perdita di memoria che si verifica in caso di errori durante il caricamento della chiave privata.  <\/ul>\n<\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56387\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e 25 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b 2 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2021-44790 &#8212; \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432, \u0441\u043e\u0441\u0442\u043e\u044f\u0449\u0438\u0445 \u0438\u0437 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u0438\u0445 \u0447\u0430\u0441\u0442\u0435\u0439 (multipart). \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 Lua-\u0441\u043a\u0440\u0438\u043f\u0442\u044b \u0432\u044b\u0437\u044b\u0432\u0430\u044e\u0442 \u0444\u0443\u043d\u043a\u0446\u0438\u044e r:parsebody() \u0434\u043b\u044f \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0442\u0435\u043b\u0430 \u0437\u0430\u043f\u0440\u043e\u0441\u0430, \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0431\u0443\u0444\u0435\u0440\u0430 \u0447\u0435\u0440\u0435\u0437 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u0430. \u0424\u0430\u043a\u0442\u043e\u0432 \u043d\u0430\u043b\u0438\u0447\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-102701","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e 25 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b 2 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2021-44790 - \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e 25 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b 2 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2021-44790 - \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-12-22T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-12-22T07:36:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Rilascio del server http Apache 2.4.52 con correzione dell'overflow del buffer in mod_lua | ProHoster","description":"\u00c8 stato pubblicato il rilascio del server HTTP Apache 2.4.52, che presenta 25 modifiche e risolve 2 vulnerabilit\u00e0: CVE-2021-44790 - overflow del buffer in mod_lua, che si manifesta durante l'analisi delle richieste.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.52, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e 25 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u044b 2 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2021-44790 - \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 mod_lua, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u0440\u0430\u0437\u0431\u043e\u0440\u0435 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-http-servera-apache-2-4-52-s-ustraneniem-perepolneniya-bufera-v-mod_lua","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-12-22T07:36:38+00:00","article:modified_time":"2021-12-22T07:36:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"102701","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-12-22 07:36:51","updated":"2026-02-09 21:39:49","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/102701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=102701"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/102701\/revisions"}],"predecessor-version":[{"id":159973,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/102701\/revisions\/159973"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=102701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=102701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=102701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}