Red Hat Security Advisory: httpd24-httpd security and bug fix update
🔗 CVE IDs covered (15)
📋 Description
CVE-2021-33193 — httpd: Request splitting via HTTP/2 method injection and mod_proxy CVE-2021-34798 — httpd: NULL pointer dereference via malformed requests CVE-2021-36160 — httpd: mod_proxy_uwsgi: out-of-bounds read via a crafted request uri-path CVE-2021-39275 — httpd: Out-of-bounds write in ap_escape_quotes() via malicious input CVE-2021-44224 — httpd: possible NULL dereference or SSRF in forward proxy configurations CVE-2022-22719 — httpd: mod_lua: Use of uninitialized value of in r:parsebody CVE-2022-22721 — httpd: core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody CVE-2022-23943 — httpd: mod_sed: Read/write beyond bounds CVE-2022-26377 — httpd: mod_proxy_ajp: Possible request smuggling CVE-2022-28614 — httpd: Out-of-bounds read via ap_rwrite() CVE-2022-28615 — httpd: Out-of-bounds read in ap_strcmp_match() CVE-2022-29404 — httpd: mod_lua: DoS in r:parsebody CVE-2022-30522 — httpd: mod_sed: DoS vulnerability CVE-2022-30556 — httpd: mod_lua: Information disclosure with websockets CVE-2022-31813 — httpd: mod_proxy: X-Forwarded-For dropped by hop-by-hop mechanism
🎯 Affected products38
- Red Hat Software Collections for RHEL Workstation(v. 7)
- Red Hat Software Collections for RHEL(v. 7)
- httpd24-httpd-0:2.4.34-23.el7.5.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-0:2.4.34-23.el7.5.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-0:2.4.34-23.el7.5.src as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-0:2.4.34-23.el7.5.src as a component of Red Hat Software Collections for RHEL(v. 7)
- httpd24-httpd-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- httpd24-httpd-debuginfo-0:2.4.34-23.el7.5.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-debuginfo-0:2.4.34-23.el7.5.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-debuginfo-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-debuginfo-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- httpd24-httpd-devel-0:2.4.34-23.el7.5.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-devel-0:2.4.34-23.el7.5.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-devel-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-devel-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- httpd24-httpd-manual-0:2.4.34-23.el7.5.noarch as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-manual-0:2.4.34-23.el7.5.noarch as a component of Red Hat Software Collections for RHEL(v. 7)
- httpd24-httpd-tools-0:2.4.34-23.el7.5.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-tools-0:2.4.34-23.el7.5.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-tools-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-httpd-tools-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- httpd24-mod_ldap-0:2.4.34-23.el7.5.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-mod_ldap-0:2.4.34-23.el7.5.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-mod_ldap-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-mod_ldap-0:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- httpd24-mod_proxy_html-1:2.4.34-23.el7.5.ppc64le as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-mod_proxy_html-1:2.4.34-23.el7.5.s390x as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-mod_proxy_html-1:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL Workstation(v. 7)
- httpd24-mod_proxy_html-1:2.4.34-23.el7.5.x86_64 as a component of Red Hat Software Collections for RHEL(v. 7)
- +8 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Workaround: This flaw can be mitigated by disabling HTTP/2. More information available at: https://httpd.apache.org/docs/2.4/mod/mod_http2.html Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Disabling mod_lua and restarting httpd will mitigate this flaw. See https://access.redhat.com/articles/10649 for more information. Workaround: Set the LimitXMLRequestBody option to a value smaller than 350MB. Setting it to 0 is not recommended as it will use a hard limit (depending on 32bit or 64bit systems) which may result in an overall system out-of-memory. The default configuration is not vulnerable to this flaw, see the statement above. Workaround: Disabling mod_sed and restarting httpd will mitigate this flaw. See https://access.redhat.com/articles/10649 for more information. Workaround: Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw. Workaround: Disabling mod_lua and restarting httpd will mitigate this flaw. Workaround: Disabling mod_sed and restarting httpd will mitigate this flaw.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2022:6753
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/articles/6975397
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966728
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005119
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005124
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005128
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034672
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064319
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064320
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064322
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2094997
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2095002
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2095006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2095012
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2095015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2095018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2095020
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6753.json