CVE-2021-36160: mod_proxy_uwsgi out of bound read
A carefully crafted request uri-path can cause modproxyuwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
Other sources
An out-of-bounds read in modproxyuwsgi of httpd allows a remote unauthenticated attacker to crash the service through a crafted request. The highest threat from this vulnerability is to system availability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.51-28.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.51-28.el7 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-23.el7.5 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.38-3+deb10u8Fixed in 2.4.38-3+deb10u10Fixed in 2.4.56-1~deb11u2Fixed in 2.4.56-1~deb11u1Fixed in 2.4.57-2Fixed in 2.4.57-3Fixed in 2.4.58-1 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.49
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2021-36160?
The severity of CVE-2021-36160 is high, with a severity value of 7.5.
How does CVE-2021-36160 affect system availability?
CVE-2021-36160 can cause the service to crash, posing a threat to system availability.
Which software versions are affected by CVE-2021-36160?
CVE-2021-36160 affects versions up to exclusive 2.4.49 of the httpd package, 0:2.4.51-28.el8 and 0:2.4.51-28.el7 of jbcs-httpd24-httpd package, 0:2.4.34-23.el7.5 of httpd24-httpd package, and various versions of apache2 and uwsgi packages in Debian.
How can CVE-2021-36160 be fixed?
To fix CVE-2021-36160, it is recommended to update the affected software to the specified remedy versions provided by the respective sources (Red Hat, Debian, etc.).
Where can I find more information about CVE-2021-36160?
For more information about CVE-2021-36160, you can refer to the references provided: http://httpd.apache.org/security/vulnerabilities_24.html, https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2005125, and https://access.redhat.com/errata/RHSA-2022:1915.