First published: Wed Apr 10 2019(Updated: )
USN-3937-1 and USN-3627-1 fixed several vulnerabilities in Apache. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Simon Kappel discovered that the Apache HTTP Server mod_auth_digest module incorrectly handled threads. A remote attacker with valid credentials could possibly use this issue to authenticate using another username, bypassing access control restrictions. (CVE-2019-0217) Alex Nichols and Jakob Hirsch discovered that the Apache HTTP Server mod_authnz_ldap module incorrectly handled missing charset encoding headers. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. (CVE-2017-15710) Robert Swiecki discovered that the Apache HTTP Server incorrectly handled certain requests. A remote attacker could possibly use this issue to cause the server to crash, leading to a denial of service. (CVE-2018-1301) Nicolas Daniels discovered that the Apache HTTP Server incorrectly generated the nonce when creating HTTP Digest authentication challenges. A remote attacker could possibly use this issue to replay HTTP requests across a cluster of servers. (CVE-2018-1312)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/apache2.2-bin | <2.2.22-1ubuntu1.15 | 2.2.22-1ubuntu1.15 |
Ubuntu OpenSSH Client | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-3937-2 fixes several vulnerabilities in Apache, including CVE-2017-15710, CVE-2018-1301, and CVE-2018-1312.
These vulnerabilities can allow remote attackers to execute arbitrary code, disclose sensitive information, or cause a denial-of-service condition.
No, Apache version 2.2.22-1ubuntu1.15 is not affected by the vulnerabilities fixed in USN-3937-2.
If you are using Ubuntu 12.04 ESM with Apache, you should update to the latest version provided in USN-3937-2.
You can find more information about the vulnerabilities fixed in USN-3937-2 on the Ubuntu Security Notices website.