A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.13-3ubuntu2+esm1", "binary_name": "libapache2-mod-apreq2" }, { "binary_version": "2.13-3ubuntu2+esm1", "binary_name": "libapache2-mod-apreq2-dbgsym" }, { "binary_version": "2.13-3ubuntu2+esm1", "binary_name": "libapache2-request-perl" }, { "binary_version": "2.13-3ubuntu2+esm1", "binary_name": "libapache2-request-perl-dbgsym" }, { "binary_version": "2.13-3ubuntu2+esm1", "binary_name": "libapreq2-3" }, { "binary_version": "2.13-3ubuntu2+esm1", "binary_name": "libapreq2-3-dbgsym" }, { "binary_version": "2.13-3ubuntu2+esm1", "binary_name": "libapreq2-dev" }, { "binary_version": "2.13-3ubuntu2+esm1", "binary_name": "libapreq2-doc" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.13-4ubuntu2+esm1", "binary_name": "libapache2-mod-apreq2" }, { "binary_version": "2.13-4ubuntu2+esm1", "binary_name": "libapache2-mod-apreq2-dbgsym" }, { "binary_version": "2.13-4ubuntu2+esm1", "binary_name": "libapache2-request-perl" }, { "binary_version": "2.13-4ubuntu2+esm1", "binary_name": "libapache2-request-perl-dbgsym" }, { "binary_version": "2.13-4ubuntu2+esm1", "binary_name": "libapreq2-3" }, { "binary_version": "2.13-4ubuntu2+esm1", "binary_name": "libapreq2-3-dbgsym" }, { "binary_version": "2.13-4ubuntu2+esm1", "binary_name": "libapreq2-dev" }, { "binary_version": "2.13-4ubuntu2+esm1", "binary_name": "libapreq2-doc" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.13-7~deb10u1build0.18.04.1", "binary_name": "libapache2-mod-apreq2" }, { "binary_version": "2.13-7~deb10u1build0.18.04.1", "binary_name": "libapache2-mod-apreq2-dbgsym" }, { "binary_version": "2.13-7~deb10u1build0.18.04.1", "binary_name": "libapache2-request-perl" }, { "binary_version": "2.13-7~deb10u1build0.18.04.1", "binary_name": "libapache2-request-perl-dbgsym" }, { "binary_version": "2.13-7~deb10u1build0.18.04.1", "binary_name": "libapreq2-3" }, { "binary_version": "2.13-7~deb10u1build0.18.04.1", "binary_name": "libapreq2-3-dbgsym" }, { "binary_version": "2.13-7~deb10u1build0.18.04.1", "binary_name": "libapreq2-dev" }, { "binary_version": "2.13-7~deb10u1build0.18.04.1", "binary_name": "libapreq2-doc" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.13-7", "binary_name": "libapache2-mod-apreq2" }, { "binary_version": "2.13-7", "binary_name": "libapache2-mod-apreq2-dbgsym" }, { "binary_version": "2.13-7", "binary_name": "libapache2-request-perl" }, { "binary_version": "2.13-7", "binary_name": "libapache2-request-perl-dbgsym" }, { "binary_version": "2.13-7", "binary_name": "libapreq2-3" }, { "binary_version": "2.13-7", "binary_name": "libapreq2-3-dbgsym" }, { "binary_version": "2.13-7", "binary_name": "libapreq2-dev" }, { "binary_version": "2.13-7", "binary_name": "libapreq2-doc" } ] }