Out-of-bounds read in Apache HTTP Server - CVE-2021-36160
Published: September 17, 2021 / Updated: October 2, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in the mod_proxy_uwsgi module in Apache HTTP Server. A remote attacker can send an HTTP request with specially crafted uri-path, trigger an out-of-bounds read and perform a denial of service (DoS) attack.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
Ubuntu
openEuler
Fedora
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-brotli (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
apache2 (Debian package)
httpd24-httpd (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-jansson (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
SUSE Linux Enterprise Module for Packagehub Subpackages
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
mod_http2
mod_md
apache2-bin (Ubuntu package)
apache2 (Ubuntu package)
apache2-debugsource
apache2
apache2-debuginfo
apache2-worker-debuginfo
apache2-devel
apache2-prefork
apache2-prefork-debuginfo
apache2-utils
apache2-utils-debuginfo
apache2-worker
apache2-doc
httpd
httpd-devel
httpd-tools
mod_ldap
mod_proxy_html
mod_session
mod_ssl
httpd-filesystem
httpd-manual
apache2-event-debuginfo
apache2-event
httpd-help
httpd-debugsource
httpd-debuginfo
app-admin/apache-tools
www-servers/apache
EasyApache
IBM Rational Build Forge
IBM Aspera Orchestrator
Traffix SDC
IBM Business Automation Manager Open Editions
Maximo Application Suite - IoT Component
JBoss Core Services
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2021-36160
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-31.el7jbcs, 0.4.10-31.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-16.el7jbcs, 1.0.0-16.el8jbcs
jbcs-httpd24-brotli (Red Hat package) - addressed in versions 1.0.9-2.el7jbcs, 1.0.9-2.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-98.el7jbcs, 1.6.1-98.el8jbcs
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.7.0-6.el7jbcs, 1.7.0-6.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-17.el7jbcs, 1.15.19-17.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.43.0-10.el7jbcs, 1.43.0-10.el8jbcs
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.0-15.el7jbcs, 2.4.0-15.el8jbcs
apache2 (Debian package) - addressed in versions 2.4.38-3+deb10u6, 2.4.51-1~deb11u1
httpd24-httpd (Red Hat package) - update to 2.4.34-23.el7.5
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.51-28.el7jbcs, 2.4.51-28.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-19.el7jbcs, 2.9.3-19.el8jbcs
jbcs-httpd24-jansson (Red Hat package) - addressed in versions 2.14-1.el7jbcs, 2.14-1.el8jbcs
EasyApache - update to 4 2021-9-22
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.83.1-6.el7jbcs, 7.83.1-6.el8jbcs
IBM Rational Build Forge - update to 8.0.0.21
IBM Business Automation Manager Open Editions - update to 9.0.1
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.17-9.el7jbcs, 1.3.17-9.el8jbcs
mod_http2 - update to 1.15.7-5
mod_md - update to 2.0.8-8
apache2-bin (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.17, 2.4.29-1ubuntu4.18, 2.4.41-4ubuntu3.5, 2.4.41-4ubuntu3.6, 2.4.46-4ubuntu1.2, 2.4.46-4ubuntu1.3, 2.4.182ubuntu3.17+esm3
apache2 (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.17, 2.4.29-1ubuntu4.18, 2.4.41-4ubuntu3.5, 2.4.41-4ubuntu3.6, 2.4.46-4ubuntu1.2, 2.4.46-4ubuntu1.3, 2.4.182ubuntu3.17+esm3
apache2-debugsource - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2 - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-debuginfo - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-worker-debuginfo - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-devel - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-prefork - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-prefork-debuginfo - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-utils - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-utils-debuginfo - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-worker - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
apache2-doc - addressed in versions 2.4.33-3.55.1, 2.4.43-3.32.1
httpd - update to 2.4.37-47.0.1
httpd-devel - update to 2.4.37-47.0.1
httpd-tools - update to 2.4.37-47.0.1
mod_ldap - update to 2.4.37-47.0.1
mod_proxy_html - update to 2.4.37-47.0.1
mod_session - update to 2.4.37-47.0.1
mod_ssl - update to 2.4.37-47.0.1
httpd-filesystem - update to 2.4.37-47.0.1
httpd-manual - update to 2.4.37-47.0.1
apache2-event-debuginfo - update to 2.4.43-3.32.1
apache2-event - update to 2.4.43-3.32.1
httpd-filesystem - update to 2.4.43-9
httpd-help - update to 2.4.43-9
mod_session - update to 2.4.43-9
httpd-debugsource - update to 2.4.43-9
mod_proxy_html - update to 2.4.43-9
mod_ldap - update to 2.4.43-9
httpd-debuginfo - update to 2.4.43-9
httpd-tools - update to 2.4.43-9
httpd-devel - update to 2.4.43-9
mod_md - update to 2.4.43-9
mod_ssl - update to 2.4.43-9
httpd - update to 2.4.43-9
httpd - addressed in versions 2.4.49-1.fc34, 2.4.49-1.fc35
JBoss Core Services - update to 2.4.51
app-admin/apache-tools - update to 2.4.54
www-servers/apache - update to 2.4.54
IBM Aspera Orchestrator - update to 4.0.1.2b9681
IBM Aspera Faspex for Windows - update to 4.4.2
IBM Aspera Faspex for Linux - update to 4.4.2
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
- http://httpd.apache.org/security/vulnerabilities_24.html
- https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70@%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d@%3Ccvs.httpd.apache.org%3E
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Multiple vulnerabilities in cPanel EasyApache
- Debian update for apache2
- Amazon Linux AMI update for httpd24
- Information disclosure in IBM Rational Build Forge
- Red Hat Enterprise Linux 8 update for the httpd:2.4 module
- SUSE update for apache2
- SUSE update for apache2
- Ubuntu update for apache2
- Ubuntu update for apache2
- Ubuntu update for apache2
- Gentoo update for Apache HTTPD
- Red Hat Software Collections update for httpd24-httpd
- Multiple vulnerabilities in IBM Aspera Faspex
- Multiple vulnerabilities in Red Hat JBoss Core Services
- Out-of-bounds read in IBM Aspera Orchestrator
- F5 Traffix SDC update for Apache HTTPD
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- openEuler update for httpd
- Fedora 34 update for httpd
- Fedora 35 update for httpd
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Anolis OS update for httpd:2.4 module