QID 198413
Date Published: 2021-06-28
QID 198413: Ubuntu Security Notification for Apache HTTP Server vulnerabilities (USN-4994-1)
The apache mod_proxy_http module incorrectly handled certain requests.
The apache mod_auth_digest module incorrectly handled certain digest nonces.
The apache mod_session module incorrectly handled certain cookie headers.
The apache mod_session module incorrectly handled certain sessionheader values.
The new mergeslashes configuration option resulted in unexpected behaviour in certain situations.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
a remote attacker could possibly use this issue to cause apache to crash, resulting in a denial of service.
This issue only affected ubuntu 20.04 lts, ubuntu 20.10, and ubuntu 21.04. (
Cve-2020-13950).
A remote attacker could possibly use this issue to cause apache to crash, resulting in a denial of service.
(cve-2020-35452).
A remote attacker could possibly use this issue to cause apache to crash, resulting in a denial of service.
(cve-2021-26690).
A remote attacker could use this issue to cause apache to crash, resulting in a denial of service, or possibly execute arbitrary code. (
Cve-2021-26691).
(cve-2021-30641).
- USN-4994-1 -
usn.ubuntu.com/4994-1
CVEs related to QID 198413
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4994-1 | Ubuntu Linux |
|