Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-6506-1

Ubuntu Security Notice 6506-1 - David Shoon discovered that the Apache HTTP Server mod_macro module incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. Prof. Sven Dietrich, Isa Jafarov, Prof. Heejo Lee, and Choongin Lee discovered that the Apache HTTP Server incorrectly handled certain HTTP/2 connections. A remote attacker could possibly use this issue to cause the server to consume resources, leading to a denial of service. This issue only affected Ubuntu 23.04, and Ubuntu 23.10.

Packet Storm
#vulnerability#mac#ubuntu#dos#apache
==========================================================================Ubuntu Security Notice USN-6506-1November 22, 2023apache2 vulnerabilities==========================================================================A security issue affects these releases of Ubuntu and its derivatives:- Ubuntu 23.10- Ubuntu 23.04- Ubuntu 22.04 LTS- Ubuntu 20.04 LTSSummary:Several security issues were fixed in Apache HTTP Server.Software Description:- apache2: Apache HTTP serverDetails:David Shoon discovered that the Apache HTTP Server mod_macro moduleincorrectly handled certain memory operations. A remote attacker couldpossibly use this issue to cause the server to crash, resulting in a denialof service. (CVE-2023-31122)Prof. Sven Dietrich, Isa Jafarov, Prof. Heejo Lee, and Choongin Leediscovered that the Apache HTTP Server incorrectly handled certain HTTP/2connections. A remote attacker could possibly use this issue to cause theserver to consume resources, leading to a denial of service. This issueonly affected Ubuntu 23.04, and Ubuntu 23.10. (CVE-2023-43622)Will Dormann and David Warren discovered that the Apache HTTP Serverincorrectly handled memory when handling HTTP/2 connections. A remoteattacker could possibly use this issue to cause the server to consumeresources, leading to a denial of service. (CVE-2023-45802)Update instructions:The problem can be corrected by updating your system to the followingpackage versions:Ubuntu 23.10:   apache2                         2.4.57-2ubuntu2.1Ubuntu 23.04:   apache2                         2.4.55-1ubuntu2.1Ubuntu 22.04 LTS:   apache2                         2.4.52-1ubuntu4.7Ubuntu 20.04 LTS:   apache2                         2.4.41-4ubuntu3.15In general, a standard system update will make all the necessary changes.References:   https://ubuntu.com/security/notices/USN-6506-1   CVE-2023-31122, CVE-2023-43622, CVE-2023-45802Package Information:   https://launchpad.net/ubuntu/+source/apache2/2.4.57-2ubuntu2.1   https://launchpad.net/ubuntu/+source/apache2/2.4.55-1ubuntu2.1   https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.7   https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.15

Related news

Debian Security Advisory 5662-1

Debian Linux Security Advisory 5662-1 - Multiple vulnerabilities have been discovered in the Apache HTTP server, which may result in HTTP response splitting or denial of service.

Red Hat Security Advisory 2024-1317-03

Red Hat Security Advisory 2024-1317-03 - Red Hat JBoss Core Services Apache HTTP Server 2.4.57 Service Pack 3 is now available. Issues addressed include buffer overflow, cross site scripting, information leakage, out of bounds read, and use-after-free vulnerabilities.

Red Hat Security Advisory 2024-1316-03

Red Hat Security Advisory 2024-1316-03 - Red Hat JBoss Core Services Apache HTTP Server 2.4.57 Service Pack 3 is now available. Issues addressed include cross site scripting, information leakage, and out of bounds read vulnerabilities.

Red Hat Security Advisory 2023-7626-03

Red Hat Security Advisory 2023-7626-03 - Red Hat JBoss Core Services Apache HTTP Server 2.4.57 Service Pack 2 is now available. Issues addressed include buffer overflow, denial of service, information leakage, and integer overflow vulnerabilities.

Red Hat Security Advisory 2023-7625-03

Red Hat Security Advisory 2023-7625-03 - An update is now available for Red Hat JBoss Core Services. Issues addressed include buffer overflow, denial of service, and information leakage vulnerabilities.

Ubuntu Security Notice USN-6510-1

Ubuntu Security Notice 6510-1 - David Shoon discovered that the Apache HTTP Server mod_macro module incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service.

Packet Storm: Latest News

htmly 2.9.9 Cross Site Scripting