Soubory cookie nám pomáhají zlepšovat naše webové stránky. Přečtěte si naše zásady používání souborů cookie .

AS-2022-005: Apache HTTP Server

2022-05-16

Severity

Important

Status

Resolved


Statement

The Apache Software Foundation announced multiple vulnerabilities that have been fixed in the latest release of Apache HTTP Server 2.4.53.

CVE-2022-22719 and CVE-2022-22720 will affect ASUSTOR products with Apache HTTP Server 2.4.52 installed.

  • Updates with Apache HTTP Server 2.4.53 has been released on App Central for ADM 4.0 and above.
  • Apache HTTP Server patch has been applied on ADM 3.5.9.RTD2 to resolve these issues.

CVE-2022-22721 and CVE-2022-23943 will not affect ASUSTOR products.


Affected Products

Product Severity Fixed Release Availability
ADM 4.0 Important Upgrade Apache HTTP Server to 2.4.53.r12 or above.
ADM 3.5 Moderate Upgrade to 3.5.9.RTD2 or above.

Mitigation

For ADM 3.5, administrators can disable Web Server service to mitigate the specific vulnerabilities. In environments where Web Server is still needed, changing the default Web Server port (80 and 443) can be used as temporary mitigation.


Detail

  • CVE-2022-22719
    • Severity: Moderate
    • A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
  • CVE-2022-22720
    • Severity: Important
    • Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling.
  • CVE-2022-22721
    • Severity: Low
    • If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
  • CVE-2022-23943
    • Severity: Important
    • Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

Reference


Revision

Revision Date Description
1 2022-04-20 Initial public release.
2 2022-05-04 Update Apache HTTP Server to 2.4.53.r12 for fixing the issues on ADM 4.0.
Update mitigation information for ADM 3.5.
3 2022-05-16 Release ADM 3.5.9.RTD2 to update Apache HTTP Server patch for fixing the issues.