[Git][security-tracker-team/security-tracker][master] CVE-2021-33193/apache2: link patches from distros with close versions

Sylvain Beucler (@beuc) beuc at debian.org
Tue Sep 13 17:07:34 BST 2022



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e0e1200b by Sylvain Beucler at 2022-09-13T17:56:32+02:00
CVE-2021-33193/apache2: link patches from distros with close versions

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -90781,11 +90781,13 @@ CVE-2021-33194 (golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allow
 CVE-2021-33193 (A crafted method sent through HTTP/2 will bypass validation and be for ...)
 	- apache2 2.4.48-4
 	[bullseye] - apache2 2.4.48-3.1+deb11u1
-	[buster] - apache2 <postponed> (Revisit when a suitable backport is available for 2.4.38)
+	[buster] - apache2 <postponed> (Fix along with next DLA)
 	[stretch] - apache2 <postponed> (Revisit when a suitable backport is available for 2.4.25)
 	NOTE: https://portswigger.net/research/http2
-	NOTE: https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c
+	NOTE: https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c (2.4.49)
 	NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2021-33193
+	NOTE: https://git.centos.org/rpms/httpd/blob/c496dea5e0b6e82a9f503e973fc5d5ea93a94180/f/SOURCES/httpd-2.4.37-CVE-2021-33193.patch (2.4.37)
+	NOTE: http://launchpadlibrarian.net/559974735/apache2_2.4.29-1ubuntu4.16_2.4.29-1ubuntu4.17.diff.gz (2.4.29)
 CVE-2021-33192 (A vulnerability in the HTML pages of Apache Jena Fuseki allows an atta ...)
 	- apache-jena <unfixed> (bug #1014982)
 	NOTE: https://lists.apache.org/thread/sq6q94q0prqwr9vdm2wptglcq1kv98k8



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0e1200b0e9aa4ead96fc224e9e5f7a401a0e3da

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e0e1200b0e9aa4ead96fc224e9e5f7a401a0e3da
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220913/322199f0/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list