apache2 (2.4.54-2ubuntu1.2) kinetic-security; urgency=medium
* SECURITY UPDATE: HTTP request splitting with mod_rewrite and mod_proxy
- debian/patches/CVE-2023-25690-1.patch: don't forward invalid query
strings in modules/http2/mod_proxy_http2.c,
modules/mappers/mod_rewrite.c, modules/proxy/mod_proxy_ajp.c,
modules/proxy/mod_proxy_balancer.c, modules/proxy/mod_proxy_http.c,
modules/proxy/mod_proxy_wstunnel.c.
- debian/patches/CVE-2023-25690-2.patch: Fix missing APLOGNO in
modules/http2/mod_proxy_http2.c.
- CVE-2023-25690
* SECURITY UPDATE: mod_proxy_uwsgi HTTP response splitting
- debian/patches/CVE-2023-27522.patch: stricter backend HTTP response
parsing/validation in modules/proxy/mod_proxy_uwsgi.c.
- CVE-2023-27522
-- Marc Deslauriers <
marc.deslauriers@ubuntu.com> Wed, 08 Mar 2023 12:31:20 -0500
提示,有2个漏洞需要修补,看来是需要修补这2个漏洞,前一个漏洞牵扯5个c文件,后一个牵扯1个c文件,网络安全维护人员提示有漏洞,还是要升级至2.4.56,只有找时间源代码编译安装了。多谢