USN-6885-4: Apache HTTP Server regression
USN-6885-1 fixed a vulnerability in Apache. The patch for CVE-2024-38474 was incomplete and caused regressions. This update provides the fix for that issue. Original advisory details: Orange Tsai discovered that the Apache HTTP Server modrewrite module incorrectly handled certain substitutions. A remote attacker could possibly use this issue to execute scripts in directories not directly reachable by any URL, or cause a denial of service. Some environments may require using the new UnsafeAllow3F flag to handle unsafe substitutions. (CVE-2024-38474)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6885-4?
USN-6885-4 addresses a critical vulnerability in the Apache HTTP Server mod_rewrite module that could lead to security issues.
How do I fix USN-6885-4?
To fix USN-6885-4, update your Apache package to the latest versions specified for your Ubuntu release.
What versions are affected by USN-6885-4?
USN-6885-4 affects multiple versions of Apache, specifically those in Ubuntu 16.04 to 24.10 prior to their respective patched versions.
What is the cause of the issues addressed by USN-6885-4?
The issues in USN-6885-4 were caused by an incomplete patch for CVE-2024-38474 that led to regressions in the Apache HTTP Server.
Who discovered the vulnerability related to USN-6885-4?
The vulnerability related to USN-6885-4 was discovered by security researcher Orange Tsai.