ALAS2-2020-1427

Related Vulnerabilities: CVE-2020-1927   CVE-2020-1934  

In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. (CVE-2020-1934) In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL. (CVE-2020-1927)

ALAS2-2020-1427


Amazon Linux 2 Security Advisory: ALAS-2020-1427
Advisory Release Date: 2020-05-19 18:32 Pacific
Advisory Updated Date: 2020-05-20 20:16 Pacific
Severity: Low

Issue Overview:

In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. (CVE-2020-1934)


In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL. (CVE-2020-1927)


Affected Packages:

httpd


Issue Correction:
Run yum update httpd to update your system.

New Packages:
aarch64:
    httpd-2.4.43-1.amzn2.aarch64
    httpd-devel-2.4.43-1.amzn2.aarch64
    httpd-tools-2.4.43-1.amzn2.aarch64
    mod_ssl-2.4.43-1.amzn2.aarch64
    mod_md-2.4.43-1.amzn2.aarch64
    mod_proxy_html-2.4.43-1.amzn2.aarch64
    mod_ldap-2.4.43-1.amzn2.aarch64
    mod_session-2.4.43-1.amzn2.aarch64
    httpd-debuginfo-2.4.43-1.amzn2.aarch64

i686:
    httpd-2.4.43-1.amzn2.i686
    httpd-devel-2.4.43-1.amzn2.i686
    httpd-tools-2.4.43-1.amzn2.i686
    mod_ssl-2.4.43-1.amzn2.i686
    mod_md-2.4.43-1.amzn2.i686
    mod_proxy_html-2.4.43-1.amzn2.i686
    mod_ldap-2.4.43-1.amzn2.i686
    mod_session-2.4.43-1.amzn2.i686
    httpd-debuginfo-2.4.43-1.amzn2.i686

noarch:
    httpd-manual-2.4.43-1.amzn2.noarch
    httpd-filesystem-2.4.43-1.amzn2.noarch

src:
    httpd-2.4.43-1.amzn2.src

x86_64:
    httpd-2.4.43-1.amzn2.x86_64
    httpd-devel-2.4.43-1.amzn2.x86_64
    httpd-tools-2.4.43-1.amzn2.x86_64
    mod_ssl-2.4.43-1.amzn2.x86_64
    mod_md-2.4.43-1.amzn2.x86_64
    mod_proxy_html-2.4.43-1.amzn2.x86_64
    mod_ldap-2.4.43-1.amzn2.x86_64
    mod_session-2.4.43-1.amzn2.x86_64
    httpd-debuginfo-2.4.43-1.amzn2.x86_64