Out-of-bounds read in Apache HTTP Server - CVE-2021-36160

 

Out-of-bounds read in Apache HTTP Server - CVE-2021-36160

Published: September 17, 2021 / Updated: October 2, 2024


Vulnerability identifier: #VU56680
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36160
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in the mod_proxy_uwsgi module in Apache HTTP Server. A remote attacker can send an HTTP request with specially crafted uri-path, trigger an out-of-bounds read and perform a denial of service (DoS) attack.


Affected software

Apache HTTP Server
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
Ubuntu
openEuler
Fedora
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
apache2 (Debian package)
httpd24-httpd (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
SUSE Linux Enterprise Module for Packagehub Subpackages
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
mod_http2
mod_md
apache2-bin (Ubuntu package)
apache2 (Ubuntu package)
apache2-debugsource
apache2
apache2-debuginfo
apache2-worker-debuginfo
apache2-devel
apache2-prefork
apache2-prefork-debuginfo
apache2-utils
apache2-utils-debuginfo
apache2-worker
apache2-doc
httpd
httpd-devel
httpd-tools
mod_ldap
mod_proxy_html
mod_session
mod_ssl
httpd-filesystem
httpd-manual
apache2-event-debuginfo
apache2-event
httpd-help
httpd-debugsource
httpd-debuginfo
app-admin/apache-tools
www-servers/apache
EasyApache
IBM Rational Build Forge
IBM Aspera Orchestrator
Traffix SDC
IBM Business Automation Manager Open Editions
Maximo Application Suite - IoT Component
JBoss Core Services
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2021-36160

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.49
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-31.el7jbcs, 0.4.10-31.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-16.el7jbcs, 1.0.0-16.el8jbcs
jbcs-httpd24-brotli (Red Hat package) - addressed in versions 1.0.9-2.el7jbcs, 1.0.9-2.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-98.el7jbcs, 1.6.1-98.el8jbcs
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.7.0-6.el7jbcs, 1.7.0-6.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-17.el7jbcs, 1.15.19-17.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.43.0-10.el7jbcs, 1.43.0-10.el8jbcs
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs
apache2 (Debian package) - addressed in versions 2.4.38-3+deb10u6, 2.4.51-1~deb11u1
httpd24-httpd (Red Hat package) - update to 2.4.34-23.el7.5
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-28.el7jbcs, 2.4.51-28.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-19.el7jbcs, 2.9.3-19.el8jbcs
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.14-1.el7jbcs, 2.14-1.el8jbcs
EasyApache - update to 4 2021-9-22
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.83.1-6.el7jbcs, 7.83.1-6.el8jbcs
IBM Rational Build Forge - update to 8.0.0.21
IBM Business Automation Manager Open Editions - update to 9.0.1
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.17-9.el7jbcs, 1.3.17-9.el8jbcs
mod_http2 - update to 1.15.7-5
mod_md - update to 2.0.8-8
apache2-bin (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.17, 2.4.29-1ubuntu4.18, 2.4.41-4ubuntu3.5, 2.4.41-4ubuntu3.6, 2.4.46-4ubuntu1.2, 2.4.46-4ubuntu1.3, 2.4.182ubuntu3.17+esm3
apache2 (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.17, 2.4.29-1ubuntu4.18, 2.4.41-4ubuntu3.5, 2.4.41-4ubuntu3.6, 2.4.46-4ubuntu1.2, 2.4.46-4ubuntu1.3, 2.4.182ubuntu3.17+esm3
apache2-debugsource - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2 - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-debuginfo - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-worker-debuginfo - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-devel - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-prefork - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-prefork-debuginfo - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-utils - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-utils-debuginfo - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-worker - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-doc - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
httpd - update to 2.4.37-47.0.1
httpd-devel - update to 2.4.37-47.0.1
httpd-tools - update to 2.4.37-47.0.1
mod_ldap - update to 2.4.37-47.0.1
mod_proxy_html - update to 2.4.37-47.0.1
mod_session - update to 2.4.37-47.0.1
mod_ssl - update to 2.4.37-47.0.1
httpd-filesystem - update to 2.4.37-47.0.1
httpd-manual - update to 2.4.37-47.0.1
apache2-event-debuginfo - update to 2.4.43-3.32.1
apache2-event - update to 2.4.43-3.32.1
httpd-filesystem - update to 2.4.43-9
httpd-help - update to 2.4.43-9
mod_session - update to 2.4.43-9
httpd-debugsource - update to 2.4.43-9
mod_proxy_html - update to 2.4.43-9
mod_ldap - update to 2.4.43-9
httpd-debuginfo - update to 2.4.43-9
httpd-tools - update to 2.4.43-9
httpd-devel - update to 2.4.43-9
mod_md - update to 2.4.43-9
mod_ssl - update to 2.4.43-9
httpd - update to 2.4.43-9
httpd - addressed in versions 2.4.49-1.fc34, 2.4.49-1.fc35
JBoss Core Services - update to 2.4.51
app-admin/apache-tools - update to 2.4.54
www-servers/apache - update to 2.4.54
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Aspera Faspex for Linux - update to 4.4.2
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins