241 lines
11 KiB
JSON
241 lines
11 KiB
JSON
{
|
||
"Definition": [
|
||
{
|
||
"ID": "oval:org.altlinux.errata:def:20231437",
|
||
"Version": "oval:org.altlinux.errata:def:20231437",
|
||
"Class": "patch",
|
||
"Metadata": {
|
||
"Title": "ALT-PU-2023-1437: package `apache2` update to version 2.4.56-alt1",
|
||
"AffectedList": [
|
||
{
|
||
"Family": "unix",
|
||
"Platforms": [
|
||
"ALT Linux branch c9f2"
|
||
],
|
||
"Products": [
|
||
"ALT SPWorkstation",
|
||
"ALT SPServer"
|
||
]
|
||
}
|
||
],
|
||
"References": [
|
||
{
|
||
"RefID": "ALT-PU-2023-1437",
|
||
"RefURL": "https://errata.altlinux.org/ALT-PU-2023-1437",
|
||
"Source": "ALTPU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-01738",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-01738",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-02021",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-02021",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-25690",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-25690",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-27522",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-27522",
|
||
"Source": "CVE"
|
||
}
|
||
],
|
||
"Description": "This update upgrades apache2 to version 2.4.56-alt1. \nSecurity Fix(es):\n\n * BDU:2023-01738: Уязвимость модуля mod_proxy веб-сервера Apache HTTP Server, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)\n\n * BDU:2023-02021: Уязвимость компонента mod_proxy_uwsgi веб-сервера Apache HTTP Server связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю выполнять атаку \u0026quot;контрабанда HTTP-запросов\u0026quot;\n\n * CVE-2023-25690: Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.\n\n\n\n\nConfigurations are affected when mod_proxy is enabled along with some form of RewriteRule\n or ProxyPassMatch in which a non-specific pattern matches\n some portion of the user-supplied request-target (URL) data and is then\n re-inserted into the proxied request-target using variable \nsubstitution. For example, something like:\n\n\n\n\nRewriteEngine on\nRewriteRule \"^/here/(.*)\" \"http://example.com:8080/elsewhere?$1\"; [P]\nProxyPassReverse /here/ http://example.com:8080/\n\n\nRequest splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.\n\n\n\n\n * CVE-2023-27522: HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55.\n\nSpecial characters in the origin response header can truncate/split the response forwarded to the client.\n\n\n",
|
||
"Advisory": {
|
||
"From": "errata.altlinux.org",
|
||
"Severity": "Critical",
|
||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||
"Issued": {
|
||
"Date": "2023-03-15"
|
||
},
|
||
"Updated": {
|
||
"Date": "2023-03-15"
|
||
},
|
||
"BDUs": [
|
||
{
|
||
"ID": "BDU:2023-01738",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
|
||
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
||
"CWE": "CWE-444",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-01738",
|
||
"Impact": "Critical",
|
||
"Public": "20230202"
|
||
},
|
||
{
|
||
"ID": "BDU:2023-02021",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:P/I:C/A:P",
|
||
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L",
|
||
"CWE": "CWE-444",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-02021",
|
||
"Impact": "High",
|
||
"Public": "20230129"
|
||
}
|
||
],
|
||
"CVEs": [
|
||
{
|
||
"ID": "CVE-2023-25690",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-25690",
|
||
"Impact": "Critical",
|
||
"Public": "20230307"
|
||
},
|
||
{
|
||
"ID": "CVE-2023-27522",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-27522",
|
||
"Impact": "High",
|
||
"Public": "20230307"
|
||
}
|
||
],
|
||
"AffectedCPEs": {
|
||
"CPEs": [
|
||
"cpe:/o:alt:spworkstation:8.4",
|
||
"cpe:/o:alt:spserver:8.4"
|
||
]
|
||
}
|
||
}
|
||
},
|
||
"Criteria": {
|
||
"Operator": "AND",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:4001",
|
||
"Comment": "ALT Linux must be installed"
|
||
}
|
||
],
|
||
"Criterias": [
|
||
{
|
||
"Operator": "OR",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437001",
|
||
"Comment": "apache2 is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437002",
|
||
"Comment": "apache2-ab is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437003",
|
||
"Comment": "apache2-base is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437004",
|
||
"Comment": "apache2-cgi-bin is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437005",
|
||
"Comment": "apache2-cgi-bin-printenv is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437006",
|
||
"Comment": "apache2-cgi-bin-test-cgi is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437007",
|
||
"Comment": "apache2-compat is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437008",
|
||
"Comment": "apache2-configs-A1PROXIED is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437009",
|
||
"Comment": "apache2-datadirs is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437010",
|
||
"Comment": "apache2-devel is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437011",
|
||
"Comment": "apache2-docs is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437012",
|
||
"Comment": "apache2-full is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437013",
|
||
"Comment": "apache2-htcacheclean is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437014",
|
||
"Comment": "apache2-htcacheclean-control is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437015",
|
||
"Comment": "apache2-html is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437016",
|
||
"Comment": "apache2-htpasswd is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437017",
|
||
"Comment": "apache2-httpd-event is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437018",
|
||
"Comment": "apache2-httpd-prefork is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437019",
|
||
"Comment": "apache2-httpd-worker is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437020",
|
||
"Comment": "apache2-icons is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437021",
|
||
"Comment": "apache2-manual is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437022",
|
||
"Comment": "apache2-manual-addons is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437023",
|
||
"Comment": "apache2-mod_cache_disk is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437024",
|
||
"Comment": "apache2-mod_ldap is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437025",
|
||
"Comment": "apache2-mod_proxy_html is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437026",
|
||
"Comment": "apache2-mod_ssl is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437027",
|
||
"Comment": "apache2-mod_ssl-compat is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437028",
|
||
"Comment": "apache2-mods is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437029",
|
||
"Comment": "apache2-suexec is earlier than 1:2.4.56-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231437030",
|
||
"Comment": "rpm-build-apache2 is earlier than 1:2.4.56-alt1"
|
||
}
|
||
]
|
||
}
|
||
]
|
||
}
|
||
}
|
||
]
|
||
} |