[Git][security-tracker-team/security-tracker][master] CVE-2021-33193/apache2: link patches from distros with close versions
Sylvain Beucler (@beuc)
beuc at debian.org
Tue Sep 13 17:07:34 BST 2022
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e0e1200b by Sylvain Beucler at 2022-09-13T17:56:32+02:00
CVE-2021-33193/apache2: link patches from distros with close versions
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -90781,11 +90781,13 @@ CVE-2021-33194 (golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allow
CVE-2021-33193 (A crafted method sent through HTTP/2 will bypass validation and be for ...)
- apache2 2.4.48-4
[bullseye] - apache2 2.4.48-3.1+deb11u1
- [buster] - apache2 <postponed> (Revisit when a suitable backport is available for 2.4.38)
+ [buster] - apache2 <postponed> (Fix along with next DLA)
[stretch] - apache2 <postponed> (Revisit when a suitable backport is available for 2.4.25)
NOTE: https://portswigger.net/research/http2
- NOTE: https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c
+ NOTE: https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c (2.4.49)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2021-33193
+ NOTE: https://git.centos.org/rpms/httpd/blob/c496dea5e0b6e82a9f503e973fc5d5ea93a94180/f/SOURCES/httpd-2.4.37-CVE-2021-33193.patch (2.4.37)
+ NOTE: http://launchpadlibrarian.net/559974735/apache2_2.4.29-1ubuntu4.16_2.4.29-1ubuntu4.17.diff.gz (2.4.29)
CVE-2021-33192 (A vulnerability in the HTML pages of Apache Jena Fuseki allows an atta ...)
- apache-jena <unfixed> (bug #1014982)
NOTE: https://lists.apache.org/thread/sq6q94q0prqwr9vdm2wptglcq1kv98k8
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0e1200b0e9aa4ead96fc224e9e5f7a401a0e3da
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0e1200b0e9aa4ead96fc224e9e5f7a401a0e3da
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220913/322199f0/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list