{"id":"CLSA-2021-1635458969","summary":"Fix CVE(s): CVE-2021-40438, CVE-2021-34798, CVE-2021-39275","details":"\n   * SECURITY UPDATE: Buffer overflow with crafted input\n     - debian/patches/CVE-2021-39275.patch:ap_escape_quotes() may write beyond\n       the end of a buffer when given malicious input\n     - CVE-2021-39275\n   * SECURITY UPDATE: Malformed requests may cause the server to dereference a NULL pointer\n     - debian/patches/CVE-2021-34798.patch: prevent ap_increment_counts() from pointer\n       dereference without check\n     - CVE-2021-34798\n   * SECURITY UPDATE: A crafted request uri-path can cause mod_proxy to forward the request\n     to an origin server choosen by the remote user.\n     - debian/patches/CVE-2021-40438.patch: add checks for the configured UDS path\n     - CVE-2021-40438","modified":"2026-06-04T10:03:57.053419935Z","published":"2021-10-28T22:09:29Z","upstream":["CVE-2021-34798","CVE-2021-39275","CVE-2021-40438"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16_04/CLSA-2021-1635458969"}],"affected":[{"package":{"name":"apache2","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18-2ubuntu3.19"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635458969.json"}},{"package":{"name":"apache2-bin","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-bin?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18-2ubuntu3.19"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635458969.json"}},{"package":{"name":"apache2-data","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-data?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18-2ubuntu3.19"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635458969.json"}},{"package":{"name":"apache2-dev","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-dev?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18-2ubuntu3.19"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635458969.json"}},{"package":{"name":"apache2-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18-2ubuntu3.19"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635458969.json"}},{"package":{"name":"apache2-suexec-custom","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-suexec-custom?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18-2ubuntu3.19"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635458969.json"}},{"package":{"name":"apache2-suexec-pristine","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-suexec-pristine?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18-2ubuntu3.19"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635458969.json"}},{"package":{"name":"apache2-utils","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/apache2-utils?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18-2ubuntu3.19"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2021-1635458969.json"}}],"schema_version":"1.7.5"}