Message ID | 20230309165925.22876-1-matthias.fischer@ipfire.org |
---|---|
State | Accepted |
Commit | ee1d6a7c3a8a2904d78f83c4a37784ec87f3b368 |
Headers |
Return-Path: <development-bounces@lists.ipfire.org> Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-384) server-digest SHA384 client-signature ECDSA (P-384) client-digest SHA384) (Client CN "mail01.haj.ipfire.org", Issuer "R3" (verified OK)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4PXb541Gxwz3ww4 for <patchwork@web04.haj.ipfire.org>; Thu, 9 Mar 2023 16:59:36 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-384) server-digest SHA384 client-signature ECDSA (P-384) client-digest SHA384) (Client CN "mail02.haj.ipfire.org", Issuer "R3" (verified OK)) by mail01.ipfire.org (Postfix) with ESMTPS id 4PXb514SVxzq4; Thu, 9 Mar 2023 16:59:33 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [127.0.0.1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4PXb512qj2z30GL; Thu, 9 Mar 2023 16:59:33 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-384) server-digest SHA384 client-signature ECDSA (P-384) client-digest SHA384) (Client CN "mail01.haj.ipfire.org", Issuer "R3" (verified OK)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4PXb4z3CGBz2xmx for <development@lists.ipfire.org>; Thu, 9 Mar 2023 16:59:31 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-384) server-digest SHA384) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4PXb4y4W3YzQS for <development@lists.ipfire.org>; Thu, 9 Mar 2023 16:59:30 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1678381170; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=he06lMjEf05IMr1io+O1QO0XSAz/FiB69/mV/r8+wVM=; b=DWxJjqoLy7Vwag03yRgd+2QHRi/4pRPkvzvbWyfcTDxa7J/chpkGILCoh8awQwCr8hLP84 D5xkkAy7ozQt7HCg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1678381170; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=he06lMjEf05IMr1io+O1QO0XSAz/FiB69/mV/r8+wVM=; b=aU1bFHhVq5EppQ2s40uHXNyWjI3EYcckRhl0fZQbhQx07n5HCsn+3DonwL2Ep5Mx2qRsP9 CPonKt+yYL/Fo9y0aqc3O5NOWMyUEjJ/giCK60uqnGxqe4cZL4TUwVqg0xCiQRrPfIEAts VBQ9k9vVFuJ72bS/e4EPiNkYqCCYQtgXIaEkORfZZfsAEIZPur4s90/FECGzDW2YQKctMI 138z0alXbLrLrmU5sZ32VjH/8k/zVLFNGSvW6UTkxPhMIHy8UmcKHKIucDgL5UrQ8IeXYR ETBNqoUcBelEMUGIdBmwQ9MfxkFZ40sXD3z1sbSXsw9/Jjnu5mNDFnn6BWXnPA== From: Matthias Fischer <matthias.fischer@ipfire.org> To: development@lists.ipfire.org Subject: [PATCH] apache: Update to 2.4.56 Date: Thu, 9 Mar 2023 17:59:25 +0100 Message-Id: <20230309165925.22876-1-matthias.fischer@ipfire.org> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: development@lists.ipfire.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: IPFire development talk <development.lists.ipfire.org> List-Unsubscribe: <https://lists.ipfire.org/mailman/options/development>, <mailto:development-request@lists.ipfire.org?subject=unsubscribe> List-Archive: <http://lists.ipfire.org/pipermail/development/> List-Post: <mailto:development@lists.ipfire.org> List-Help: <mailto:development-request@lists.ipfire.org?subject=help> List-Subscribe: <https://lists.ipfire.org/mailman/listinfo/development>, <mailto:development-request@lists.ipfire.org?subject=subscribe> Errors-To: development-bounces@lists.ipfire.org Sender: "Development" <development-bounces@lists.ipfire.org> |
Series |
apache: Update to 2.4.56
|
|
Commit Message
Matthias Fischer
March 9, 2023, 4:59 p.m. UTC
For details see:
https://dlcdn.apache.org/httpd/CHANGES_2.4.56
"Changes with Apache 2.4.56
*) SECURITY: CVE-2023-27522: Apache HTTP Server: mod_proxy_uwsgi
HTTP response splitting (cve.mitre.org)
HTTP Response Smuggling vulnerability in Apache HTTP Server via
mod_proxy_uwsgi. This issue affects Apache HTTP Server: from
2.4.30 through 2.4.55.
Special characters in the origin response header can
truncate/split the response forwarded to the client.
Credits: Dimas Fariski Setyawan Putra (nyxsorcerer)
*) SECURITY: CVE-2023-25690: HTTP request splitting with
mod_rewrite and mod_proxy (cve.mitre.org)
Some mod_proxy configurations on Apache HTTP Server versions
2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations are affected when mod_proxy is enabled along with
some form of RewriteRule
or ProxyPassMatch in which a non-specific pattern matches
some portion of the user-supplied request-target (URL) data and
is then
re-inserted into the proxied request-target using variable
substitution. For example, something like:
RewriteEngine on
RewriteRule "^/here/(.*)" "
http://example.com:8080/elsewhere?$1"
http://example.com:8080/elsewhere ; [P]
ProxyPassReverse /here/ http://example.com:8080/
http://example.com:8080/
Request splitting/smuggling could result in bypass of access
controls in the proxy server, proxying unintended URLs to
existing origin servers, and cache poisoning.
Credits: Lars Krapf of Adobe
*) rotatelogs: Add -T flag to allow subsequent rotated logfiles to be
truncated without the initial logfile being truncated. [Eric Covener]
*) mod_ldap: LDAPConnectionPoolTTL should accept negative values in order to
allow connections of any age to be reused. Up to now, a negative value
was handled as an error when parsing the configuration file. PR 66421.
[nailyk <bzapache nailyk.fr>, Christophe Jaillet]
*) mod_proxy_ajp: Report an error if the AJP backend sends an invalid number
of headers. [Ruediger Pluem]
*) mod_md:
- Enabling ED25519 support and certificate transparency information when
building with libressl v3.5.0 and newer. Thanks to Giovanni Bechis.
- MDChallengeDns01 can now be configured for individual domains.
Thanks to Jérôme Billiras (@bilhackmac) for the initial PR.
- Fixed a bug found by Jérôme Billiras (@bilhackmac) that caused the challenge
teardown not being invoked as it should.
[Stefan Eissing]
*) mod_http2: client resets of HTTP/2 streams led to unwanted 500 errors
reported in access logs and error documents. The processing of the
reset was correct, only unneccesary reporting was caused.
[Stefan Eissing]
*) mod_proxy_uwsgi: Stricter backend HTTP response parsing/validation.
[Yann Ylavic]"
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
---
lfs/apache2 | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
Comments
Reviewed-by: Peter Müller <peter.mueller@ipfire.org> > For details see: > https://dlcdn.apache.org/httpd/CHANGES_2.4.56 > > "Changes with Apache 2.4.56 > > *) SECURITY: CVE-2023-27522: Apache HTTP Server: mod_proxy_uwsgi > HTTP response splitting (cve.mitre.org) > HTTP Response Smuggling vulnerability in Apache HTTP Server via > mod_proxy_uwsgi. This issue affects Apache HTTP Server: from > 2.4.30 through 2.4.55. > Special characters in the origin response header can > truncate/split the response forwarded to the client. > Credits: Dimas Fariski Setyawan Putra (nyxsorcerer) > > *) SECURITY: CVE-2023-25690: HTTP request splitting with > mod_rewrite and mod_proxy (cve.mitre.org) > Some mod_proxy configurations on Apache HTTP Server versions > 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. > Configurations are affected when mod_proxy is enabled along with > some form of RewriteRule > or ProxyPassMatch in which a non-specific pattern matches > some portion of the user-supplied request-target (URL) data and > is then > re-inserted into the proxied request-target using variable > substitution. For example, something like: > RewriteEngine on > RewriteRule "^/here/(.*)" " > http://example.com:8080/elsewhere?$1" > http://example.com:8080/elsewhere ; [P] > ProxyPassReverse /here/ http://example.com:8080/ > http://example.com:8080/ > Request splitting/smuggling could result in bypass of access > controls in the proxy server, proxying unintended URLs to > existing origin servers, and cache poisoning. > Credits: Lars Krapf of Adobe > > *) rotatelogs: Add -T flag to allow subsequent rotated logfiles to be > truncated without the initial logfile being truncated. [Eric Covener] > > *) mod_ldap: LDAPConnectionPoolTTL should accept negative values in order to > allow connections of any age to be reused. Up to now, a negative value > was handled as an error when parsing the configuration file. PR 66421. > [nailyk <bzapache nailyk.fr>, Christophe Jaillet] > > *) mod_proxy_ajp: Report an error if the AJP backend sends an invalid number > of headers. [Ruediger Pluem] > > *) mod_md: > - Enabling ED25519 support and certificate transparency information when > building with libressl v3.5.0 and newer. Thanks to Giovanni Bechis. > - MDChallengeDns01 can now be configured for individual domains. > Thanks to Jérôme Billiras (@bilhackmac) for the initial PR. > - Fixed a bug found by Jérôme Billiras (@bilhackmac) that caused the challenge > teardown not being invoked as it should. > [Stefan Eissing] > > *) mod_http2: client resets of HTTP/2 streams led to unwanted 500 errors > reported in access logs and error documents. The processing of the > reset was correct, only unneccesary reporting was caused. > [Stefan Eissing] > > *) mod_proxy_uwsgi: Stricter backend HTTP response parsing/validation. > [Yann Ylavic]" > > Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org> > --- > lfs/apache2 | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/lfs/apache2 b/lfs/apache2 > index 7e1ef7911..402aa8567 100644 > --- a/lfs/apache2 > +++ b/lfs/apache2 > @@ -25,7 +25,7 @@ > > include Config > > -VER = 2.4.55 > +VER = 2.4.56 > > THISAPP = httpd-$(VER) > DL_FILE = $(THISAPP).tar.bz2 > @@ -45,7 +45,7 @@ objects = $(DL_FILE) > > $(DL_FILE) = $(DL_FROM)/$(DL_FILE) > > -$(DL_FILE)_BLAKE2 = 98e9ec41aa3ccbbe533672ba6de8421e1f0cb5a4b4a06d0cf26c676945bcd5ebe66a1fd21d941ad8ff2c9183565ce542a5643730bbee5972934008652924945b > +$(DL_FILE)_BLAKE2 = f9aaf5038543aeec79d5b8615b1b2120fe321966280574c685070f2356f8f1dba1d55a9a25f46cb5ecdd6e3f03785fe7a4e1b965506896cb889720728aa18101 > > install : $(TARGET) >
diff --git a/lfs/apache2 b/lfs/apache2 index 7e1ef7911..402aa8567 100644 --- a/lfs/apache2 +++ b/lfs/apache2 @@ -25,7 +25,7 @@ include Config -VER = 2.4.55 +VER = 2.4.56 THISAPP = httpd-$(VER) DL_FILE = $(THISAPP).tar.bz2 @@ -45,7 +45,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 98e9ec41aa3ccbbe533672ba6de8421e1f0cb5a4b4a06d0cf26c676945bcd5ebe66a1fd21d941ad8ff2c9183565ce542a5643730bbee5972934008652924945b +$(DL_FILE)_BLAKE2 = f9aaf5038543aeec79d5b8615b1b2120fe321966280574c685070f2356f8f1dba1d55a9a25f46cb5ecdd6e3f03785fe7a4e1b965506896cb889720728aa18101 install : $(TARGET)