A carefully crafted request uri-path can cause modproxyuwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "apache2"
},
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "apache2-bin"
},
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "apache2-data"
},
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "apache2-dev"
},
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "apache2-ssl-dev"
},
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "apache2-suexec-custom"
},
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "apache2-suexec-pristine"
},
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "apache2-utils"
},
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "libapache2-mod-md"
},
{
"binary_version": "2.4.41-4ubuntu3.5",
"binary_name": "libapache2-mod-proxy-uwsgi"
}
]
}