===========================================================================
ZMCIRT Vulnerability Bulletin
ZMC-2022.18.01.0800
httpd: Multiple vulnerabilities
18th January 2022
===========================================================================
Product: httpd
Publisher: Red Hat
Operating System: Red Hat
Impact/Access: Execute Arbitrary Code/Commands -- Remote/Unauthenticated
Denial of Service -- Remote/Unauthenticated
Access Confidential Data -- Remote/Unauthenticated
Reduced Security -- Remote/Unauthenticated
Resolution: Patch/Upgrade
CVE Names: CVE-2021-44790 CVE-2021-39275 CVE-2021-34798
CVE-2021-26691
Reference: ESB-2021.3784
Original Bulletin:
https://access.redhat.com/errata/RHSA-2022:0143
- --------------------------BEGIN INCLUDED TEXT--------------------
- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Important: httpd security update
Advisory ID: RHSA-2022:0143-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2022:0143
Issue date: 2022-01-17
CVE Names: CVE-2021-26691 CVE-2021-34798 CVE-2021-39275
CVE-2021-44790
=====================================================================
1. Summary:
An update for httpd is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3. Description:
The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.
Security Fix(es):
* httpd: mod_lua: Possible buffer overflow when parsing multipart content
(CVE-2021-44790)
* httpd: mod_session: Heap overflow via a crafted SessionHeader value
(CVE-2021-26691)
* httpd: NULL pointer dereference via malformed requests (CVE-2021-34798)
* httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
(CVE-2021-39275)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
After installing the updated packages, the httpd daemon will be restarted
automatically.
5. Bugs fixed (https://bugzilla.redhat.com/):
1966732 - CVE-2021-26691 httpd: mod_session: Heap overflow via a crafted SessionHeader value
2005119 - CVE-2021-39275 httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
2005128 - CVE-2021-34798 httpd: NULL pointer dereference via malformed requests
2034674 - CVE-2021-44790 httpd: mod_lua: Possible buffer overflow when parsing multipart content
6. Package List:
Red Hat Enterprise Linux Client Optional (v. 7):
Source:
httpd-2.4.6-97.el7_9.4.src.rpm
noarch:
httpd-manual-2.4.6-97.el7_9.4.noarch.rpm
x86_64:
httpd-2.4.6-97.el7_9.4.x86_64.rpm
httpd-debuginfo-2.4.6-97.el7_9.4.x86_64.rpm
httpd-devel-2.4.6-97.el7_9.4.x86_64.rpm
httpd-tools-2.4.6-97.el7_9.4.x86_64.rpm
mod_ldap-2.4.6-97.el7_9.4.x86_64.rpm
mod_proxy_html-2.4.6-97.el7_9.4.x86_64.rpm
mod_session-2.4.6-97.el7_9.4.x86_64.rpm
mod_ssl-2.4.6-97.el7_9.4.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
Source:
httpd-2.4.6-97.el7_9.4.src.rpm
noarch:
httpd-manual-2.4.6-97.el7_9.4.noarch.rpm
x86_64:
httpd-2.4.6-97.el7_9.4.x86_64.rpm
httpd-debuginfo-2.4.6-97.el7_9.4.x86_64.rpm
httpd-devel-2.4.6-97.el7_9.4.x86_64.rpm
httpd-tools-2.4.6-97.el7_9.4.x86_64.rpm
mod_ldap-2.4.6-97.el7_9.4.x86_64.rpm
mod_proxy_html-2.4.6-97.el7_9.4.x86_64.rpm
mod_session-2.4.6-97.el7_9.4.x86_64.rpm
mod_ssl-2.4.6-97.el7_9.4.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
httpd-2.4.6-97.el7_9.4.src.rpm
noarch:
httpd-manual-2.4.6-97.el7_9.4.noarch.rpm
ppc64:
httpd-2.4.6-97.el7_9.4.ppc64.rpm
httpd-debuginfo-2.4.6-97.el7_9.4.ppc64.rpm
httpd-devel-2.4.6-97.el7_9.4.ppc64.rpm
httpd-tools-2.4.6-97.el7_9.4.ppc64.rpm
mod_session-2.4.6-97.el7_9.4.ppc64.rpm
mod_ssl-2.4.6-97.el7_9.4.ppc64.rpm
ppc64le:
httpd-2.4.6-97.el7_9.4.ppc64le.rpm
httpd-debuginfo-2.4.6-97.el7_9.4.ppc64le.rpm
httpd-devel-2.4.6-97.el7_9.4.ppc64le.rpm
httpd-tools-2.4.6-97.el7_9.4.ppc64le.rpm
mod_session-2.4.6-97.el7_9.4.ppc64le.rpm
mod_ssl-2.4.6-97.el7_9.4.ppc64le.rpm
s390x:
httpd-2.4.6-97.el7_9.4.s390x.rpm
httpd-debuginfo-2.4.6-97.el7_9.4.s390x.rpm
httpd-devel-2.4.6-97.el7_9.4.s390x.rpm
httpd-tools-2.4.6-97.el7_9.4.s390x.rpm
mod_session-2.4.6-97.el7_9.4.s390x.rpm
mod_ssl-2.4.6-97.el7_9.4.s390x.rpm
x86_64:
httpd-2.4.6-97.el7_9.4.x86_64.rpm
httpd-debuginfo-2.4.6-97.el7_9.4.x86_64.rpm
httpd-devel-2.4.6-97.el7_9.4.x86_64.rpm
httpd-tools-2.4.6-97.el7_9.4.x86_64.rpm
mod_session-2.4.6-97.el7_9.4.x86_64.rpm
mod_ssl-2.4.6-97.el7_9.4.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
httpd-debuginfo-2.4.6-97.el7_9.4.ppc64.rpm
mod_ldap-2.4.6-97.el7_9.4.ppc64.rpm
mod_proxy_html-2.4.6-97.el7_9.4.ppc64.rpm
ppc64le:
httpd-debuginfo-2.4.6-97.el7_9.4.ppc64le.rpm
mod_ldap-2.4.6-97.el7_9.4.ppc64le.rpm
mod_proxy_html-2.4.6-97.el7_9.4.ppc64le.rpm
s390x:
httpd-debuginfo-2.4.6-97.el7_9.4.s390x.rpm
mod_ldap-2.4.6-97.el7_9.4.s390x.rpm
mod_proxy_html-2.4.6-97.el7_9.4.s390x.rpm
x86_64:
httpd-debuginfo-2.4.6-97.el7_9.4.x86_64.rpm
mod_ldap-2.4.6-97.el7_9.4.x86_64.rpm
mod_proxy_html-2.4.6-97.el7_9.4.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
httpd-2.4.6-97.el7_9.4.src.rpm
noarch:
httpd-manual-2.4.6-97.el7_9.4.noarch.rpm
x86_64:
httpd-2.4.6-97.el7_9.4.x86_64.rpm
httpd-debuginfo-2.4.6-97.el7_9.4.x86_64.rpm
httpd-devel-2.4.6-97.el7_9.4.x86_64.rpm
httpd-tools-2.4.6-97.el7_9.4.x86_64.rpm
mod_session-2.4.6-97.el7_9.4.x86_64.rpm
mod_ssl-2.4.6-97.el7_9.4.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
httpd-debuginfo-2.4.6-97.el7_9.4.x86_64.rpm
mod_ldap-2.4.6-97.el7_9.4.x86_64.rpm
mod_proxy_html-2.4.6-97.el7_9.4.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2021-26691
https://access.redhat.com/security/cve/CVE-2021-34798
https://access.redhat.com/security/cve/CVE-2021-39275
https://access.redhat.com/security/cve/CVE-2021-44790
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/
ZMCIRT has made every effort to ensure that the information contained
in this document is accurate. However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. ZMCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.
===========================================================================
Internet Email: report@cirt.zm
Telephone: 7070
ZMCIRT personnel answer during Zambian business hours
which are 8am to 5pm.
On call after hours for member emergencies only.
===========================================================================
Copyright @2023 ZAMBIA CIRT