Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.rc > #334267
| From | Tobias Frost <tobi@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.rc |
| Subject | Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption |
| Date | 2022-12-30 11:10 +0100 |
| Message-ID | <FIkuT-eiXY-3@gated-at.bofh.it> (permalink) |
| References | <EYMSm-3gp8-1@gated-at.bofh.it> <F1C0p-52SG-9@gated-at.bofh.it> <F1ElA-54dV-7@gated-at.bofh.it> <EYMSm-3gp8-1@gated-at.bofh.it> <F1ElA-54dV-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
I was trying to triage this CVE and *maybe* those revisions are related:
r1894937 ("apreq_parse_headers: Discard CRLF of folded values.")
r1894940 ("reindent (no functional change).")
r1894977 ("Follow up to r1894937: Fix setting of empty value.")
r1895054 ("Follow up to r1894937: Always eat CRLF at the end of header value.")
diff:
http://svn.apache.org/viewvc/httpd/apreq/trunk/library/parser_header.c?r1=1894937&r2=1895054&pathrev=1895054&diff_format=h
Those SVN commits have been introduced at the beginning of the 2.17 release cycle, so
would match the description "up to 2.16"…
Said that, there are not many changes between 2.13 and 2.17…
IMHHO using 2.17 might be an option to evaluate. However, someone with more perland apache2 modules knowledge should
double check:
- Apache2 Module Magic Number for the apache2 module has been bumped, which according to the comment:
> The Apache2 Module Magic Number for use in the Apache 2.x module structures
> This gets bumped if changes in th4e API will break third party applications
> using this apache2 module
Looking at the changes for the module, with 2.13 released on r1041502,
the changes up to the MMM update are only those as in attached r1041792-1042894.diff
(between r1041502 and r1041792 there are only changes in regards to the new dev cycle, i.e s/2.13/2.14)
Not sure how that would break API… I do not see any other changes to the apache2 until recently, which is still unreleased, past 2.17)
- ./glue/perl/xsbuilder/tables/APR/Request/CallbackTable.pm is almost empty >>2.13 … No idea what that means…
(attached the diff between 2.13 and 2.15. It's the same, except date, for 2.17)
--
tobi (in the hope the analysis helps…)
Back to linux.debian.bugs.rc | Previous | Next — Next in thread | Find similar | Unroll thread
Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption Tobias Frost <tobi@debian.org> - 2022-12-30 11:10 +0100
Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption Salvatore Bonaccorso <carnil@debian.org> - 2022-12-30 16:20 +0100
Bug#1018191: libapreq2: CVE-2022-22728: multipart form parse memory corruption Tobias Frost <tobi@debian.org> - 2022-12-30 17:30 +0100
csiph-web