USN-4113-1

Source
https://ubuntu.com/security/notices/USN-4113-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4113-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4113-1
Related
Published
2019-08-29T22:31:46.431140Z
Modified
2019-08-29T22:31:46.431140Z
Summary
apache2 vulnerabilities
Details

Stefan Eissing discovered that the HTTP/2 implementation in Apache did not properly handle upgrade requests from HTTP/1.1 to HTTP/2 in some situations. A remote attacker could use this to cause a denial of service (daemon crash). This issue only affected Ubuntu 18.04 LTS and Ubuntu 19.04. (CVE-2019-0197)

Craig Young discovered that a memory overwrite error existed in Apache when performing HTTP/2 very early pushes in some situations. A remote attacker could use this to cause a denial of service (daemon crash). This issue only affected Ubuntu 18.04 LTS and Ubuntu 19.04. (CVE-2019-10081)

Craig Young discovered that a read-after-free error existed in the HTTP/2 implementation in Apache during connection shutdown. A remote attacker could use this to possibly cause a denial of service (daemon crash) or possibly expose sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 19.04. (CVE-2019-10082)

Matei Badanoiu discovered that the mod_proxy component of Apache did not properly filter URLs when reporting errors in some configurations. A remote attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks. (CVE-2019-10092)

Daniel McCarney discovered that mod_remoteip component of Apache contained a stack buffer overflow when parsing headers from a trusted intermediary proxy in some situations. A remote attacker controlling a trusted proxy could use this to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 19.04. (CVE-2019-10097)

Yukitsugu Sasaki discovered that the mod_rewrite component in Apache was vulnerable to open redirects in some situations. A remote attacker could use this to possibly expose sensitive information or bypass intended restrictions. (CVE-2019-10098)

Jonathan Looney discovered that the HTTP/2 implementation in Apache did not properly limit the amount of buffering for client connections in some situations. A remote attacker could use this to cause a denial of service (unresponsive daemon). This issue only affected Ubuntu 18.04 LTS and Ubuntu 19.04. (CVE-2019-9517)

References

Affected packages

Ubuntu:16.04:LTS / apache2

Package

Name
apache2
Purl
pkg:deb/ubuntu/apache2?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.18-2ubuntu3.12

Affected versions

2.*

2.4.12-2ubuntu2
2.4.17-1ubuntu1
2.4.17-2ubuntu1
2.4.17-3ubuntu1
2.4.18-1ubuntu1
2.4.18-2ubuntu1
2.4.18-2ubuntu2
2.4.18-2ubuntu3
2.4.18-2ubuntu3.1
2.4.18-2ubuntu3.2
2.4.18-2ubuntu3.3
2.4.18-2ubuntu3.4
2.4.18-2ubuntu3.5
2.4.18-2ubuntu3.7
2.4.18-2ubuntu3.8
2.4.18-2ubuntu3.9
2.4.18-2ubuntu3.10

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-bin"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-bin-dbgsym"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-data"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-dbg"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-dbgsym"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-dev"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-dev-dbgsym"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-doc"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-suexec-custom"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-suexec-custom-dbgsym"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-suexec-pristine"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-suexec-pristine-dbgsym"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-utils"
        },
        {
            "binary_version": "2.4.18-2ubuntu3.12",
            "binary_name": "apache2-utils-dbgsym"
        }
    ]
}

Ubuntu:18.04:LTS / apache2

Package

Name
apache2
Purl
pkg:deb/ubuntu/apache2?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.29-1ubuntu4.10

Affected versions

2.*

2.4.27-2ubuntu3
2.4.29-1ubuntu1
2.4.29-1ubuntu2
2.4.29-1ubuntu3
2.4.29-1ubuntu4
2.4.29-1ubuntu4.1
2.4.29-1ubuntu4.2
2.4.29-1ubuntu4.3
2.4.29-1ubuntu4.4
2.4.29-1ubuntu4.5
2.4.29-1ubuntu4.6
2.4.29-1ubuntu4.7
2.4.29-1ubuntu4.8

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2"
        },
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2-bin"
        },
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2-data"
        },
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2-dbg"
        },
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2-dev"
        },
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2-doc"
        },
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2-ssl-dev"
        },
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2-suexec-custom"
        },
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2-suexec-pristine"
        },
        {
            "binary_version": "2.4.29-1ubuntu4.10",
            "binary_name": "apache2-utils"
        }
    ]
}