Release Info

Advisory: CLSA-2023:1689009164

OS: Ubuntu 16.04 ELS

Public date: 2023-07-10 13:12:46

Project: apache2

Version: 1:2.4.18-2ubuntu3.17+tuxcare.els11

Errata link: https://errata.cloudlinux.com/ubuntu16-els/CLSA-2023-1689009164.html

Changelog

* SECURITY UPDATE: mod_lua may denial of service in r:parsebody(0) - debian/patches/CVE-2022-29404.patch: use a liberal default limit for LimitRequestBody of 1GB to prevent a denial of service caused by a malicious lua script request - CVE-2022-29404

Update

Update command: apt-get update apt-get --only-upgrade install apache2*

Packages list

apache2_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb apache2-bin_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb apache2-data_2.4.18-2ubuntu3.17+tuxcare.els11_all.deb apache2-dev_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb apache2-doc_2.4.18-2ubuntu3.17+tuxcare.els11_all.deb apache2-suexec-custom_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb apache2-suexec-pristine_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb apache2-utils_2.4.18-2ubuntu3.17+tuxcare.els11_amd64.deb

CVEs

CVE-2022-29404