AIX Open Source

AIX Open Source

Share your experiences and connect with fellow developers to discover how to build and manage open source software for the AIX operating system

 View Only
  • 1.  httpd - CVE-2021-44224 and CVE-2021-44790 - Update to 2.4.52 or later

    Posted Tue December 28, 2021 01:27 PM
    - A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included). (CVE-2021-44224)
    - A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier. (CVE-2021-44790)

    Please upgrade the httpd package to 2.4.52 or later

    Thank you!


    ------------------------------
    Lisa Isaly
    ------------------------------


  • 2.  RE: httpd - CVE-2021-44224 and CVE-2021-44790 - Update to 2.4.52 or later

    Posted Wed January 05, 2022 11:50 AM
    Thanks for reporting. We will work on to update httpd for these CVEs.

    ------------------------------
    SANKET RATHI
    ------------------------------



  • 3.  RE: httpd - CVE-2021-44224 and CVE-2021-44790 - Update to 2.4.52 or later

    Posted Tue January 18, 2022 08:47 AM
    Thank you. Tenable is reporting this as a critical vulnerability and we'd like to have it resolved in under 30 days.

    ------------------------------
    Lisa Isaly
    ------------------------------



  • 4.  RE: httpd - CVE-2021-44224 and CVE-2021-44790 - Update to 2.4.52 or later

    Posted Mon February 07, 2022 11:24 PM
    Hi Lisa,

    I am not sure if you noticed, httpd-2.4.52 is published from AIX toolbox sometime back

    https://public.dhe.ibm.com/aix/freeSoftware/aixtoolbox/RPMS/ppc/httpd/?C=M;O=D

    ------------------------------
    SANKET RATHI
    ------------------------------