Inconsistent interpretation of HTTP requests in HTTP-Daemon - CVE-2022-31081
Published: July 14, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP requests. A remote attacker can send a specially crafted HTTP request to the server and smuggle arbitrary HTTP headers.
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
Affected software
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Gentoo Linux
Amazon Linux AMI
IBM AIX
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server
Ubuntu
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
Anolis OS
Fedora
Communications Unified Assurance
Dell EMC NetWorker vProxy
libhttp-daemon-perl (Ubuntu package)
perl-HTTP-Daemon
perl-HTTP-Daemon-doc
perl-HTTP-Daemon-tests
dev-perl/HTTP-Daemon
How to mitigate CVE-2022-31081
libhttp-daemon-perl (Ubuntu package) - addressed in versions 6.01-1ubuntu0.1, 6.06-1ubuntu0.1, 6.011ubuntu0.16.04~esm1, 6.13-1ubuntu0.1
perl-HTTP-Daemon - addressed in versions 6.01-9.5.1, 6.01-150000.3.5.1
perl-HTTP-Daemon - addressed in versions 6.15-1.fc37, 6.15-1.fc38, 6.16-1.fc36, 6.16-1.fc37, 6.16-1.fc38
perl-HTTP-Daemon - update to 6.16-1
perl-HTTP-Daemon - update to 6.16-1
perl-HTTP-Daemon-doc - update to 6.16-1
perl-HTTP-Daemon-tests - update to 6.16-1
dev-perl/HTTP-Daemon - update to 6.160.0
External References
- https://github.com/libwww-perl/HTTP-Daemon/commit/e84475de51d6fd7b29354a997413472a99db70b2
- https://github.com/libwww-perl/HTTP-Daemon/commit/8dc5269d59e2d5d9eb1647d82c449ccd880f7fd0
- https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn
- https://datatracker.ietf.org/doc/html/rfc7230#section-9.5
- https://github.com/libwww-perl/HTTP-Daemon/security/advisories/GHSA-cg8c-pxmv-w7cf
- http://metacpan.org/release/HTTP-Daemon/
- https://cwe.mitre.org/data/definitions/444.html
Related Security Bulletins
- HTTP request smuggling in HTTP::Daemon
- Ubuntu update for libhttp-daemon-perl
- Ubuntu update for libhttp-daemon-perl
- SUSE update for perl-HTTP-Daemon
- SUSE update for perl-HTTP-Daemon
- Multiple vulnerabilities in Dell EMC Data Protection Central
- Multiple vulnerabilities in Dell NetWorker vProxy
- Multiple vulnerabilities in Communications Unified Assurance
- Inconsistent interpretation of HTTP requests in IBM AIX
- Fedora 38 update for perl-HTTP-Daemon
- Fedora 37 update for perl-HTTP-Daemon
- Fedora 38 update for perl-HTTP-Daemon
- Fedora 36 update for perl-HTTP-Daemon
- Fedora 37 update for perl-HTTP-Daemon
- Amazon Linux AMI update for perl-HTTP-Daemon
- Anolis OS update for perl-HTTP-Daemon
- Gentoo update for HTTP-Daemon