Inconsistent interpretation of HTTP requests in HTTP-Daemon - CVE-2022-31081

 

Inconsistent interpretation of HTTP requests in HTTP-Daemon - CVE-2022-31081

Published: July 14, 2022


Vulnerability identifier: #VU65327
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31081
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.

The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.

Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.


Affected software

HTTP-Daemon
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Gentoo Linux
Amazon Linux AMI
IBM AIX
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Anolis OS
Fedora
Communications Unified Assurance
Dell EMC NetWorker vProxy
libhttp-daemon-perl (Ubuntu package)
perl-HTTP-Daemon
perl-HTTP-Daemon-doc
perl-HTTP-Daemon-tests
dev-perl/HTTP-Daemon

How to mitigate CVE-2022-31081

Install updates from vendor's website.

Dell EMC NetWorker vProxy - update to 4.3.0-36
libhttp-daemon-perl (Ubuntu package) - addressed in versions 6.01-1ubuntu0.1, 6.06-1ubuntu0.1, 6.011ubuntu0.16.04~esm1, 6.13-1ubuntu0.1
perl-HTTP-Daemon - addressed in versions 6.01-9.5.1, 6.01-150000.3.5.1
perl-HTTP-Daemon - addressed in versions 6.15-1.fc37, 6.15-1.fc38, 6.16-1.fc36, 6.16-1.fc37, 6.16-1.fc38
perl-HTTP-Daemon - update to 6.16-1
perl-HTTP-Daemon - update to 6.16-1
perl-HTTP-Daemon-doc - update to 6.16-1
perl-HTTP-Daemon-tests - update to 6.16-1
dev-perl/HTTP-Daemon - update to 6.160.0

External References

Related Security Bulletins