Buffer overflow in Apache HTTP Server - CVE-2021-44790

 

Buffer overflow in Apache HTTP Server - CVE-2021-44790

Published: December 20, 2021 / Updated: October 25, 2024


Vulnerability identifier: #VU59056
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-44790
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when parsing multipart content in mod_lua. A remote attacker can send a specially crafted HTTP request to the affected web server, trigger buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Apache HTTP Server
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
macOS
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
openEuler
Fedora
MELSOFT iQ AppPortal
Tenable.sc
IBM Cloud Pak System
apache2 (Debian package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
SUSE Linux Enterprise Module for Packagehub Subpackages
mod_http2
mod_md
httpd (Red Hat package)
httpd-tools
mod_ldap
mod_proxy_html
mod_session
httpd-devel
httpd-manual
httpd
mod_ssl
httpd24 (Red Hat package)
apache2-doc
apache2-worker-debuginfo
apache2
apache2-debuginfo
apache2-debugsource
apache2-example-pages
apache2-prefork
apache2-prefork-debuginfo
apache2-utils
apache2-utils-debuginfo
apache2-worker
apache2 (Ubuntu package)
apache2-bin (Ubuntu package)
apache2-devel
httpd24-httpd (Red Hat package)
httpd-filesystem
httpd-debugsource
httpd-help
httpd-debuginfo
apache2-event-debuginfo
apache2-event
app-admin/apache-tools
www-servers/apache
IBM Security SiteProtector System
Oracle Communications Operations Monitor
RecoverPoint Classic
EMC ECS
Watson Studio on Cloud Pak for Data
XtremIO X2
Maximo Application Suite - IoT Component
CTPView
Dell Secure Connect Gateway
Oracle SD-WAN Edge
IBM Rational Build Forge
Oracle Communications Session Report Manager
IBM Qradar SIEM
Instantis EnterpriseTrack
Oracle Communications Session Route Manager
Oracle Communications Element Manager
Gaia
IBM DS8000 Hardware Management Console

How to mitigate CVE-2021-44790

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.52
MELSOFT iQ AppPortal - update to 1.29F
Tenable.sc - addressed in versions Patch 202201.1, 5.20.0
IBM Cloud Pak System - update to 2.3.3.5
apache2 (Debian package) - addressed in versions 2.4.38-3+deb10u7, 2.4.52-1~deb11u2
IBM Security SiteProtector System - update to 3.1.1.18
Dell Secure Connect Gateway - update to 5.12.00.10
RecoverPoint Classic - update to 5.1 SP4 P4
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10 Interim Fix 02, 7.4.3 Fix Pack 4 Interim Fix 04, 7.5.0 Update Pack 1
IBM Rational Build Forge - update to 8.0.0.21
macOS - addressed in versions 10.15.7 19H1922, 11.6.6 20G624, 12.4 21F79
mod_http2 - update to 1.15.7-3
mod_md - update to 2.0.8-8
httpd (Red Hat package) - addressed in versions 2.4.6-45.el7_3.8, 2.4.6-67.el7_4.9, 2.4.6-89.el7_6.4, 2.4.6-90.el7_7.3
httpd-tools - addressed in versions 2.4.6-97, 2.4.37-43.0.1
mod_ldap - addressed in versions 2.4.6-97, 2.4.37-43.0.1
mod_proxy_html - addressed in versions 2.4.6-97, 2.4.37-43.0.1
mod_session - addressed in versions 2.4.6-97, 2.4.37-43.0.1
httpd-devel - addressed in versions 2.4.6-97, 2.4.37-43.0.1
httpd-manual - addressed in versions 2.4.6-97, 2.4.37-43.0.1
httpd - addressed in versions 2.4.6-97, 2.4.37-43.0.1
mod_ssl - addressed in versions 2.4.6-97, 2.4.37-43.0.1
httpd24 (Red Hat package) - update to 2.4.6-97.el7_9.4
apache2-doc - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2-worker-debuginfo - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2 - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2-debuginfo - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2-debugsource - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2-example-pages - addressed in versions 2.4.23-29.83.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2-prefork - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2-prefork-debuginfo - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2-utils - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2-utils-debuginfo - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2-worker - addressed in versions 2.4.23-29.83.1, 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
apache2 (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.21, 2.4.41-4ubuntu3.9, 2.4.46-4ubuntu1.5, 2.4.48-3.1ubuntu3.2, 2.4.182ubuntu3.17+esm4
apache2-bin (Ubuntu package) - addressed in versions 2.4.29-1ubuntu4.21, 2.4.41-4ubuntu3.9, 2.4.46-4ubuntu1.5, 2.4.48-3.1ubuntu3.2, 2.4.182ubuntu3.17+esm4
apache2-devel - addressed in versions 2.4.33-3.61.1, 2.4.51-3.37.1, 2.4.51-35.7.1, 2.4.66-150400.6.57.1
httpd24-httpd (Red Hat package) - update to 2.4.34-23.el7.1
httpd-filesystem - update to 2.4.37-43.0.1
httpd - update to 2.4.43-12
httpd-devel - update to 2.4.43-12
mod_ssl - update to 2.4.43-12
httpd-debugsource - update to 2.4.43-12
mod_md - update to 2.4.43-12
mod_proxy_html - update to 2.4.43-12
httpd-help - update to 2.4.43-12
httpd-filesystem - update to 2.4.43-12
httpd-tools - update to 2.4.43-12
mod_ldap - update to 2.4.43-12
mod_session - update to 2.4.43-12
httpd-debuginfo - update to 2.4.43-12
apache2-event-debuginfo - addressed in versions 2.4.51-3.37.1, 2.4.66-150400.6.57.1
apache2-event - addressed in versions 2.4.51-3.37.1, 2.4.66-150400.6.57.1
httpd - addressed in versions 2.4.52-1.fc35, 2.4.53-1.fc34, 2.4.53-1.fc35, 2.4.53-1.fc36
app-admin/apache-tools - update to 2.4.54
www-servers/apache - update to 2.4.54
httpd - update to 2.4.54-3
EMC ECS - update to 3.7.0.2
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
XtremIO X2 - update to 6.4.1-11
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
Oracle Communications Session Report Manager - update to 9.0
Oracle Communications Session Route Manager - update to 9.0
Oracle Communications Element Manager - update to 9.0
CTPView - update to 9.1R5
Gaia - update to R81.10 Take 55
IBM DS8000 Hardware Management Console - update to 89.30.68.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins