QID 671023
Date Published: 2021-11-24
QID 671023: EulerOS Security Update for httpd (EulerOS-SA-2021-2586)
The Apache HTTP Server is a powerful, efficient, and extensible web server.
Security Fix(es):
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation option might make it possible, with limited consequences anyway due to the size (a single byte) and the value (zero byte) of the overflow(CVE-2020-35452)
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service(CVE-2021-26690)
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow(CVE-2021-26691)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 671023
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2021-2586 | EulerOS V2.0SP3 |
|