QID 198620

Date Published: 2022-01-10

QID 198620: Ubuntu Security Notification for Apache Hypertext Transfer Protocol (HTTP) Server Vulnerabilities (USN-5212-1)

The apache http server incorrectly handled certainforward proxy requests.
The apache http server lua module incorrectlyhandled memory in the multipart parser.

A remote attacker could use this issue to causethe server to crash, resulting in a denial of service, or possibly performa server side request forgery attack.
A remote attacker could use thisissue to cause the server to crash, resulting in a denial of service, orpossibly execute arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5212-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198620

    Software Advisories
    Advisory ID Software Component Link
    USN-5212-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5212-1