Review of DLA apache2

Bastien Roucariès <[email protected]> Mon, 24 Apr 2023 07:57:25 +0000
Newsgroups gmane.linux.debian.internationalization.english
Message-ID <1756999.czd03JSYVG@portable-bastien>
Hi,

Could you review the freetext form of this DLA ?

Several vulnerabilities have been discovered in apache2 a webserver that may be used as front-end proxy for other applications.
These vulnerabilities may lead to HTTP request smuggling, and thus may lead to bypass front-end security controls.

Unfortunately, fixing these security vulnerability may need some change on configuration files. Some out of specification  RewriteRule directives that were previously silently accepted, are now rejected with error AH10409. For instance some RewriteRules that included back-references and flags [NC,L]  need now to be written with quoted like flags "[QSA,L,B= ?,BNP]".

 * CVE-2023-27522
  HTTP Response Smuggling in mod_proxy_uwsgi
 * CVE-2023-25690
    Some mod_proxy configurations allow a HTTP
    Request Smuggling attack. Configurations are affected
    when mod_proxy is enabled along with some form of RewriteRule
    or ProxyPassMatch in which a non-specific pattern matches
    some portion of the user-supplied request-target (URL)
    data and is then re-inserted into the proxied request-target
    using variable substitution.
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmRGNlMACgkQADoaLapB
CF9axw/8D3PSTnmiuK2E1brymVhMwS8AwrIpKxXOoDZsE88Tqyrcs9nLfVsOl7BT
PkeevQB9ND3Ps+qyz6IQ7MaIES5veca2slPR/KYp2oe7cTEiGToQrmYzwpcQUHY2
WOkDfLOnq+uq2lhU1mj0DkDsJ3bn/sdszonX64AzKVFKQ/5Oksy9YFWuHVG5vYhD
55wdHMDfDKiI+qB9CERiJAORKesFt39mwxdCDBj025iSKOKhN2uZz6ibd/3zgGps
zE8rC6ju0FA1+d5rsbAJqkatLpkvpCdpKtEt76MmGD6P2YPYCPaA7HOxV4ZvUPvC
PlY93LeswBtp920cKW9Gi1ipttypOE13F9mct2n6nTCE+2Vu2kfZWjztOT37SdNz
88FcTfI94rVWoOyVdJxQMeNqIZAnPgeWrK9B3k1xC+WmPoptD5raSp7aaFVmO7+g
DF6kWPiaeUzvvMa5T82Y5iyEh7rPDBnwzlPjLbDuT2BjYYf7J4byQpA5C2wXBfJP
m+u01cRnfJPvsfQ+CZdlQK57Q/UuGdPe9rCUqd1ziUuZG1tcid2fsbN5DjqQLF+p
TxxHnYZtR7ZvH+uROTpJBd+bH0e7AjxanvV/L08R0TqP9xFRKu9qkhnV4W6M/HOf
4UBnrb047zkO+Tr/oybzZy6HxQJKg4vghzq694ebxdHPixkT9IE=
=J18S
-----END PGP SIGNATURE-----