{"id":"CLSA-2022-1656430949","summary":"Fix CVE(s): CVE-2022-28615, CVE-2022-26377, CVE-2022-30522, CVE-2022-30556, CVE-2022-31813","details":"\n   * SECURITY UPDATE: mod_sed may make excessively large memory allocations\n     and trigger an abort\n     - debian/patches/CVE-2022-30522.patch: limit mod_sed memory usage\n     - CVE-2022-30522\n   * SECURITY UPDATE: HTTP request smuggling in mod_proxy_ajp\n     - debian/patches/CVE-2022-26377.patch: parse request headers in the\n       way so Transfer-Encoding has precedence over Content-Length\n     - CVE-2022-26377\n   * SECURITY UPDATE: possible out-of-bounds read in ap_strcmp_match()\n       with an extremely large input buffer\n     - debian/patches/CVE-2022-28615.patch: use apr_size_t (e.g. long)\n       for array indexing\n     - CVE-2022-28615\n   * SECURITY UPDATE: mod_lua r:wsread() may return length that points past\n     the end of the storage allocated for the buffer\n     - debian/patches/CVE-2022-30556.patch: consistently use\n       lua_websocket_readbytes() and check the return value\n     - CVE-2022-30556\n   * SECURITY UPDATE: mod_proxy may not send the X-Forwarded-* headers to the\n     origin server based on client side Connection header hop-by-hop mechanism\n     - debian/patches/CVE-2022-31813.patch: preserve original request headers\n       so an upstream knows what the original request hostname was\n     - CVE-2022-31813","modified":"2026-06-04T10:04:27.342918260Z","published":"2022-06-28T15:42:29Z","upstream":["CVE-2022-26377","CVE-2022-28615","CVE-2022-30522","CVE-2022-30556","CVE-2022-31813"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16_04/CLSA-2022-1656430949"}],"affected":[{"package":{"name":"apache2","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.18-2ubuntu3.17+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656430949.json"}},{"package":{"name":"apache2-bin","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-bin?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.18-2ubuntu3.17+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656430949.json"}},{"package":{"name":"apache2-data","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-data?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.18-2ubuntu3.17+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656430949.json"}},{"package":{"name":"apache2-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.18-2ubuntu3.17+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656430949.json"}},{"package":{"name":"apache2-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.18-2ubuntu3.17+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656430949.json"}},{"package":{"name":"apache2-suexec-custom","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-suexec-custom?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.18-2ubuntu3.17+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656430949.json"}},{"package":{"name":"apache2-suexec-pristine","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-suexec-pristine?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.18-2ubuntu3.17+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656430949.json"}},{"package":{"name":"apache2-utils","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-utils?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.4.18-2ubuntu3.17+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1656430949.json"}}],"schema_version":"1.7.5"}