USN-6885-3: Apache HTTP Server vulnerabilities
USN-6885-1 fixed several vulnerabilities in Apache. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: Orange Tsai discovered that the Apache HTTP Server modrewrite module incorrectly handled certain substitutions. A remote attacker could possibly use this issue to execute scripts in directories not directly reachable by any URL, or cause a denial of service. Some environments may require using the new UnsafeAllow3F flag to handle unsafe substitutions. (CVE-2024-38474, CVE-2024-38475) Orange Tsai discovered that the Apache HTTP Server incorrectly handled certain response headers. A remote attacker could possibly use this issue to obtain sensitive information, execute local scripts, or perform SSRF attacks. (CVE-2024-38476) Orange Tsai discovered that the Apache HTTP Server modproxy module incorrectly handled certain requests. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. (CVE-2024-38477)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6885-3?
The severity of USN-6885-3 is critical due to vulnerabilities in the Apache HTTP Server that could allow for improper handling of certain substitutions.
How do I fix USN-6885-3?
To fix USN-6885-3, update the Apache2 package to version 2.4.29-1ubuntu4.27+esm3 for Ubuntu 18.04 LTS and 2.4.18-2ubuntu3.17+esm13 for Ubuntu 16.04 LTS.
What vulnerabilities are addressed in USN-6885-3?
USN-6885-3 addresses multiple vulnerabilities related to the handling of substitutions in the mod_rewrite module of the Apache HTTP Server.
Which versions of Ubuntu are affected by USN-6885-3?
USN-6885-3 affects Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Who discovered the vulnerabilities related to USN-6885-3?
The vulnerabilities addressed in USN-6885-3 were discovered by researcher Orange Tsai.