Review of DLA apache2
Bastien Roucariès <[email protected]> Mon, 24 Apr 2023 07:57:25 +0000
| Newsgroups | gmane.linux.debian.internationalization.english |
|---|---|
| Message-ID | <1756999.czd03JSYVG@portable-bastien> |
Hi,
Could you review the freetext form of this DLA ?
Several vulnerabilities have been discovered in apache2 a webserver that may be used as front-end proxy for other applications.
These vulnerabilities may lead to HTTP request smuggling, and thus may lead to bypass front-end security controls.
Unfortunately, fixing these security vulnerability may need some change on configuration files. Some out of specification RewriteRule directives that were previously silently accepted, are now rejected with error AH10409. For instance some RewriteRules that included back-references and flags [NC,L] need now to be written with quoted like flags "[QSA,L,B= ?,BNP]".
* CVE-2023-27522
HTTP Response Smuggling in mod_proxy_uwsgi
* CVE-2023-25690
Some mod_proxy configurations allow a HTTP
Request Smuggling attack. Configurations are affected
when mod_proxy is enabled along with some form of RewriteRule
or ProxyPassMatch in which a non-specific pattern matches
some portion of the user-supplied request-target (URL)
data and is then re-inserted into the proxied request-target
using variable substitution.
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmRGNlMACgkQADoaLapB CF9axw/8D3PSTnmiuK2E1brymVhMwS8AwrIpKxXOoDZsE88Tqyrcs9nLfVsOl7BT PkeevQB9ND3Ps+qyz6IQ7MaIES5veca2slPR/KYp2oe7cTEiGToQrmYzwpcQUHY2 WOkDfLOnq+uq2lhU1mj0DkDsJ3bn/sdszonX64AzKVFKQ/5Oksy9YFWuHVG5vYhD 55wdHMDfDKiI+qB9CERiJAORKesFt39mwxdCDBj025iSKOKhN2uZz6ibd/3zgGps zE8rC6ju0FA1+d5rsbAJqkatLpkvpCdpKtEt76MmGD6P2YPYCPaA7HOxV4ZvUPvC PlY93LeswBtp920cKW9Gi1ipttypOE13F9mct2n6nTCE+2Vu2kfZWjztOT37SdNz 88FcTfI94rVWoOyVdJxQMeNqIZAnPgeWrK9B3k1xC+WmPoptD5raSp7aaFVmO7+g DF6kWPiaeUzvvMa5T82Y5iyEh7rPDBnwzlPjLbDuT2BjYYf7J4byQpA5C2wXBfJP m+u01cRnfJPvsfQ+CZdlQK57Q/UuGdPe9rCUqd1ziUuZG1tcid2fsbN5DjqQLF+p TxxHnYZtR7ZvH+uROTpJBd+bH0e7AjxanvV/L08R0TqP9xFRKu9qkhnV4W6M/HOf 4UBnrb047zkO+Tr/oybzZy6HxQJKg4vghzq694ebxdHPixkT9IE= =J18S -----END PGP SIGNATURE-----