ID

VAR-202112-1608


CVE

CVE-2021-44790


TITLE

Apache HTTP Server buffer overflow vulnerability (CNVD-2021-102386)

Trust: 0.6

sources: CNVD: CNVD-2021-102386

DESCRIPTION

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier. The server is fast, reliable, and can be expanded through simple APIs. There is a buffer overflow vulnerability in Apache HTTP Server, which originates from the r:parsebody of the product failing to correctly determine the user boundary. An attacker can use this vulnerability to cause a buffer overflow. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: httpd security update Advisory ID: RHSA-2022:1137-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:1137 Issue date: 2022-03-30 CVE Names: CVE-2021-44790 CVE-2022-22720 ===================================================================== 1. Summary: An update for httpd is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.7) - noarch, x86_64 Red Hat Enterprise Linux Server E4S (v. 7.7) - noarch, ppc64le, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server Optional E4S (v. 7.7) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional TUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server TUS (v. 7.7) - noarch, x86_64 3. Security Fix(es): * httpd: mod_lua: Possible buffer overflow when parsing multipart content (CVE-2021-44790) * httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling (CVE-2022-22720) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 2034674 - CVE-2021-44790 httpd: mod_lua: Possible buffer overflow when parsing multipart content 2064321 - CVE-2022-22720 httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.7): Source: httpd-2.4.6-90.el7_7.3.src.rpm noarch: httpd-manual-2.4.6-90.el7_7.3.noarch.rpm x86_64: httpd-2.4.6-90.el7_7.3.x86_64.rpm httpd-debuginfo-2.4.6-90.el7_7.3.x86_64.rpm httpd-devel-2.4.6-90.el7_7.3.x86_64.rpm httpd-tools-2.4.6-90.el7_7.3.x86_64.rpm mod_session-2.4.6-90.el7_7.3.x86_64.rpm mod_ssl-2.4.6-90.el7_7.3.x86_64.rpm Red Hat Enterprise Linux Server E4S (v. 7.7): Source: httpd-2.4.6-90.el7_7.3.src.rpm noarch: httpd-manual-2.4.6-90.el7_7.3.noarch.rpm ppc64le: httpd-2.4.6-90.el7_7.3.ppc64le.rpm httpd-debuginfo-2.4.6-90.el7_7.3.ppc64le.rpm httpd-devel-2.4.6-90.el7_7.3.ppc64le.rpm httpd-tools-2.4.6-90.el7_7.3.ppc64le.rpm mod_session-2.4.6-90.el7_7.3.ppc64le.rpm mod_ssl-2.4.6-90.el7_7.3.ppc64le.rpm x86_64: httpd-2.4.6-90.el7_7.3.x86_64.rpm httpd-debuginfo-2.4.6-90.el7_7.3.x86_64.rpm httpd-devel-2.4.6-90.el7_7.3.x86_64.rpm httpd-tools-2.4.6-90.el7_7.3.x86_64.rpm mod_session-2.4.6-90.el7_7.3.x86_64.rpm mod_ssl-2.4.6-90.el7_7.3.x86_64.rpm Red Hat Enterprise Linux Server TUS (v. 7.7): Source: httpd-2.4.6-90.el7_7.3.src.rpm noarch: httpd-manual-2.4.6-90.el7_7.3.noarch.rpm x86_64: httpd-2.4.6-90.el7_7.3.x86_64.rpm httpd-debuginfo-2.4.6-90.el7_7.3.x86_64.rpm httpd-devel-2.4.6-90.el7_7.3.x86_64.rpm httpd-tools-2.4.6-90.el7_7.3.x86_64.rpm mod_session-2.4.6-90.el7_7.3.x86_64.rpm mod_ssl-2.4.6-90.el7_7.3.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.7): x86_64: httpd-debuginfo-2.4.6-90.el7_7.3.x86_64.rpm mod_ldap-2.4.6-90.el7_7.3.x86_64.rpm mod_proxy_html-2.4.6-90.el7_7.3.x86_64.rpm Red Hat Enterprise Linux Server Optional E4S (v. 7.7): ppc64le: httpd-debuginfo-2.4.6-90.el7_7.3.ppc64le.rpm mod_ldap-2.4.6-90.el7_7.3.ppc64le.rpm mod_proxy_html-2.4.6-90.el7_7.3.ppc64le.rpm x86_64: httpd-debuginfo-2.4.6-90.el7_7.3.x86_64.rpm mod_ldap-2.4.6-90.el7_7.3.x86_64.rpm mod_proxy_html-2.4.6-90.el7_7.3.x86_64.rpm Red Hat Enterprise Linux Server Optional TUS (v. 7.7): x86_64: httpd-debuginfo-2.4.6-90.el7_7.3.x86_64.rpm mod_ldap-2.4.6-90.el7_7.3.x86_64.rpm mod_proxy_html-2.4.6-90.el7_7.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-44790 https://access.redhat.com/security/cve/CVE-2022-22720 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYkgMdtzjgjWX9erEAQiPfg/8DjpqRC5i5rbqFu8c7+0HQqnywj4HIFk8 rBRdH9hmVsLuJGsrtppgnaYIhQmibnJ0jBVw/SddEpJvC1YyLl06GYlesA+UOKdy 1u3Zk/11UoTP/iEdshoofeFeqoqL+Kha+LKlLuxEK4N6Ktj9CMl40olS3n/eqEwl oU+zZ7COo+1KHExMJbw02ncRFgzDU7bObskBrJ3PGav2Fr9OMUoUB1S/1qHtS+8g k+JIcQpXl8WW4qh2fAOPdjY3F3rG1Zs2vcuKuA3RFOsowBM5CiNljelHC4zruwVc zD1cUNLYyVhOdszTS8TSpcrZ7G7JVuA5MNKma7Up/jhJjiZY3Yp3gNkCsYjaR3WX 4S39ABjZTdS0I2WnJVtLDUWbEY/N+zs1NJTLdaqdXC6baB1J1brC+r4fkrct3IqU Xk51QQEQG7LvbDUm38jFvBeyXpR9Wl91RQIstfbLzojg7aXFLg9MpzhAcZVKKZK+ 3ki43MH2Qf+IKQNzQKGQloGJwyzUNQoKFl/L2FIkYy7YcP1RPd7lD6K1Y0NO2Vko dv5/Wah51ZpWm013CbM6mbUy4hf3IOEB+kyx1xkHRJr6j7JoZ0YOlIzeVe0E+VXb qNZ9OXQbheOY0uGndamjzjRExCuavmNORTa+Mdqo4SUkCd+Oh51JhqSSAaHjj+NG m1q3j1iAjdU= =+13+ -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce . 7.3) - x86_64 3. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5035-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 04, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : apache2 CVE ID : CVE-2021-44224 CVE-2021-44790 Two vulnerabilities have been discovered in the Apache HTTP server: CVE-2021-44224 When operating as a forward proxy, Apache was depending on the setup suspectible to denial of service or Server Side Request forgery. CVE-2021-44790 A buffer overflow in mod_lua may result in denial of service or potentially the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed in version 2.4.38-3+deb10u7. For the stable distribution (bullseye), these problems have been fixed in version 2.4.52-1~deb11u2. We recommend that you upgrade your apache2 packages. For the detailed security status of apache2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/apache2 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmHUdgkACgkQEMKTtsN8 TjZfAQ//YQMBeAoCcqRE1IBeBWGAKQ89Zx6bdCKbJ93Zfw93JM2wBccxyWLbPebF x38+hsZ8pv2KiAoL7QlBPatu8oHLyGR35JXZzmJe0FXhm/yJi0qPsT1UqLiclDmb XUG7D6z31Lk7fN29/Eypkc9O1sqQ2OJrA7MU95gxpxyf6otasRxiCm/j+oCjDKZx S4CFt7HNDsmQIj9JO2FOsXawJDIXJGVlI2kGEm/9nK4bxMWeAmFWrpyOTME8rEHp T2gcw46fWfOpeN6GnuLr1a0P/WQioQfDTZwg8minOuOGKqlAuhbqAcuRxWQukLCu 8vlb1sUEf8MCZGRlANFIzN2QIgxdriW/2ZlaSa4nXsoFAZaExP1dV5hZvYxFy2zT D0G0G+GnunMDhsAY0L2033zMcGyf5PrBE33pNfrmaBClT6ZR2NlCIZrlstIepeYS 4LvUZKUzTEQVQeLI/B4KiGw13eWa2T63BqvXaWcAhIvQZ/66RZqHKavI4KvpJc9h fZls+bYjTm4NjtVKJt5OcbjTVtxjLZqLXkzhng+4Xw3uxDkoKt7kzsCL3An9g5Yn R8anLiNSU666ViVWoWkjD7n7UMALg0aRs9K4RgnB0JTBgQUzf6mlS5Wq33Jdgq8B OLOTdfnxzyPt9bq7JJDQuq4CC0xAXYcYLqsvxP0B6Tq0umuOo2M= =mExg -----END PGP SIGNATURE----- . Description: Red Hat Openshift GitOps is a declarative way to implement continuous deployment for cloud native applications. Bugs fixed (https://bugzilla.redhat.com/): 2050826 - CVE-2022-24348 gitops: Path traversal and dereference of symlinks when passing Helm value files 5. 8.1) - aarch64, noarch, ppc64le, s390x, x86_64 3

Trust: 2.25

sources: NVD: CVE-2021-44790 // CNVD: CNVD-2021-102386 // VULHUB: VHN-408105 // VULMON: CVE-2021-44790 // PACKETSTORM: 166583 // PACKETSTORM: 166581 // PACKETSTORM: 169211 // PACKETSTORM: 166051 // PACKETSTORM: 166154 // PACKETSTORM: 165710 // PACKETSTORM: 165745

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-102386

AFFECTED PRODUCTS

vendor:applemodel:macosscope:gteversion:12.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.15.7

Trust: 1.0

vendor:tenablemodel:tenable.scscope:ltversion:5.20.0

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:36

Trust: 1.0

vendor:netappmodel:cloud backupscope:eqversion: -

Trust: 1.0

vendor:oraclemodel:instantis enterprisetrackscope:eqversion:17.2

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:34

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:35

Trust: 1.0

vendor:oraclemodel:communications operations monitorscope:eqversion:4.4

Trust: 1.0

vendor:oraclemodel:communications operations monitorscope:eqversion:5.0

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:11.0

Trust: 1.0

vendor:oraclemodel:instantis enterprisetrackscope:eqversion:17.3

Trust: 1.0

vendor:applemodel:macosscope:ltversion:10.15.7

Trust: 1.0

vendor:oraclemodel:communications session route managerscope:lteversion:9.0

Trust: 1.0

vendor:oraclemodel:communications session report managerscope:lteversion:9.0

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:10.0

Trust: 1.0

vendor:apachemodel:http serverscope:lteversion:2.4.51

Trust: 1.0

vendor:oraclemodel:http serverscope:eqversion:12.2.1.4.0

Trust: 1.0

vendor:oraclemodel:zfs storage appliance kitscope:eqversion:8.8

Trust: 1.0

vendor:oraclemodel:instantis enterprisetrackscope:eqversion:17.1

Trust: 1.0

vendor:applemodel:macosscope:gteversion:11.0

Trust: 1.0

vendor:oraclemodel:communications operations monitorscope:eqversion:4.3

Trust: 1.0

vendor:applemodel:macosscope:ltversion:11.6.6

Trust: 1.0

vendor:applemodel:macosscope:ltversion:12.4

Trust: 1.0

vendor:tenablemodel:tenable.scscope:gteversion:5.16.0

Trust: 1.0

vendor:oraclemodel:communications element managerscope:lteversion:9.0

Trust: 1.0

vendor:oraclemodel:http serverscope:eqversion:12.2.1.3.0

Trust: 1.0

vendor:apachemodel:http serverscope:lteversion:<=2.4.51

Trust: 0.6

sources: CNVD: CNVD-2021-102386 // NVD: CVE-2021-44790

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-44790
value: CRITICAL

Trust: 1.0

CNVD: CNVD-2021-102386
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202112-1579
value: CRITICAL

Trust: 0.6

VULHUB: VHN-408105
value: HIGH

Trust: 0.1

VULMON: CVE-2021-44790
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-44790
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

CNVD: CNVD-2021-102386
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-408105
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-44790
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2021-102386 // VULHUB: VHN-408105 // VULMON: CVE-2021-44790 // CNNVD: CNNVD-202112-1579 // NVD: CVE-2021-44790

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.1

sources: VULHUB: VHN-408105 // NVD: CVE-2021-44790

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202112-1579

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202112-1579

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-408105

PATCH

title:Patch for Apache HTTP Server buffer overflow vulnerability (CNVD-2021-102386)url:https://www.cnvd.org.cn/patchInfo/show/310311

Trust: 0.6

title:Apache HTTP Server Buffer error vulnerability fixurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=175754

Trust: 0.6

title:Red Hat: Important: httpd:2.4 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20220288 - Security Advisory

Trust: 0.1

title:Red Hat: Important: httpd24-httpd security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20220303 - Security Advisory

Trust: 0.1

title:Red Hat: Important: httpd security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20221137 - Security Advisory

Trust: 0.1

title:Red Hat: Important: Red Hat OpenShift GitOps security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20220682 - Security Advisory

Trust: 0.1

title:Red Hat: Important: httpd security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20221136 - Security Advisory

Trust: 0.1

title:Red Hat: Important: httpd security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20221138 - Security Advisory

Trust: 0.1

title:Red Hat: Important: httpd security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20221139 - Security Advisory

Trust: 0.1

title:Debian Security Advisories: DSA-5035-1 apache2 -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=eed1e8ea40feda10ee18daa68a3c5b5a

Trust: 0.1

title:Amazon Linux AMI: ALAS-2022-1560url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2022-1560

Trust: 0.1

title:Red Hat: CVE-2021-44790url:https://vulmon.com/vendoradvisory?qidtp=red_hat_cve_database&qid=CVE-2021-44790

Trust: 0.1

title:Amazon Linux 2: ALAS2-2022-1737url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux2&qid=ALAS2-2022-1737

Trust: 0.1

title:Amazon Linux 2022: ALAS2022-2022-018url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux2022&qid=ALAS2022-2022-018

Trust: 0.1

title:Tenable Security Advisories: [R1] Stand-alone Security Patch Available for Tenable.sc versions 5.16.0 to 5.19.1: Patch 202201.1url:https://vulmon.com/vendoradvisory?qidtp=tenable_security_advisories&qid=TNS-2022-03

Trust: 0.1

title:Tenable Security Advisories: [R1] Tenable.sc 5.20.0 Fixes Multiple Vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=tenable_security_advisories&qid=TNS-2022-01

Trust: 0.1

title:Red Hat: Important: Red Hat OpenShift GitOps security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20220580 - Security Advisory

Trust: 0.1

title:Apple: macOS Monterey 12.4url:https://vulmon.com/vendoradvisory?qidtp=apple_security_advisories&qid=73857ee26a600b1527481f1deacc0619

Trust: 0.1

title:-CVE-2021-44790url:https://github.com/nuPacaChi/-CVE-2021-44790

Trust: 0.1

title:SnykDeskurl:https://github.com/cretlaw/SnykDesk

Trust: 0.1

title:emo_emourl:https://github.com/emotest1/emo_emo

Trust: 0.1

title:PROJET TUTEUREurl:https://github.com/PierreChrd/py-projet-tut

Trust: 0.1

title:Tier 0 Tier 1 Tier 2url:https://github.com/Totes5706/TotesHTB

Trust: 0.1

title:Requirements vulnsearch-cve Usage vulnsearch Usage Test Sampleurl:https://github.com/kasem545/vulnsearch

Trust: 0.1

title:Skyneturl:https://github.com/bioly230/THM_Skynet

Trust: 0.1

title:Shodan Search Scripturl:https://github.com/firatesatoglu/shodanSearch

Trust: 0.1

sources: CNVD: CNVD-2021-102386 // VULMON: CVE-2021-44790 // CNNVD: CNNVD-202112-1579

EXTERNAL IDS

db:NVDid:CVE-2021-44790

Trust: 3.1

db:TENABLEid:TNS-2022-01

Trust: 1.8

db:TENABLEid:TNS-2022-03

Trust: 1.8

db:OPENWALLid:OSS-SECURITY/2021/12/20/4

Trust: 1.8

db:PACKETSTORMid:171631

Trust: 1.7

db:PACKETSTORMid:166154

Trust: 0.8

db:PACKETSTORMid:165710

Trust: 0.8

db:CNVDid:CNVD-2021-102386

Trust: 0.7

db:PACKETSTORMid:165587

Trust: 0.7

db:PACKETSTORMid:167189

Trust: 0.7

db:PACKETSTORMid:165747

Trust: 0.7

db:PACKETSTORMid:168072

Trust: 0.7

db:PACKETSTORMid:165467

Trust: 0.7

db:PACKETSTORMid:165501

Trust: 0.7

db:ICS CERTid:ICSA-22-132-02

Trust: 0.7

db:PACKETSTORMid:166583

Trust: 0.7

db:AUSCERTid:ESB-2022.0135

Trust: 0.6

db:AUSCERTid:ESB-2022.0716

Trust: 0.6

db:AUSCERTid:ESB-2022.0836

Trust: 0.6

db:AUSCERTid:ESB-2022.0039

Trust: 0.6

db:AUSCERTid:ESB-2022.0217

Trust: 0.6

db:AUSCERTid:ESB-2022.0686

Trust: 0.6

db:AUSCERTid:ESB-2022.2352

Trust: 0.6

db:AUSCERTid:ESB-2022.0064

Trust: 0.6

db:AUSCERTid:ESB-2022.2411

Trust: 0.6

db:AUSCERTid:ESB-2022.0850

Trust: 0.6

db:AUSCERTid:ESB-2022.0354

Trust: 0.6

db:AUSCERTid:ESB-2022.0171

Trust: 0.6

db:AUSCERTid:ESB-2022.0396

Trust: 0.6

db:CS-HELPid:SB2022051316

Trust: 0.6

db:CS-HELPid:SB2022042265

Trust: 0.6

db:CS-HELPid:SB2022030119

Trust: 0.6

db:CS-HELPid:SB2022051703

Trust: 0.6

db:CS-HELPid:SB2021122021

Trust: 0.6

db:CS-HELPid:SB2022060706

Trust: 0.6

db:CS-HELPid:SB2022012517

Trust: 0.6

db:CS-HELPid:SB2022010513

Trust: 0.6

db:CS-HELPid:SB2022012334

Trust: 0.6

db:CS-HELPid:SB2022010609

Trust: 0.6

db:CS-HELPid:SB2022011749

Trust: 0.6

db:CS-HELPid:SB2022021427

Trust: 0.6

db:CS-HELPid:SB2022012003

Trust: 0.6

db:CS-HELPid:SB2022060811

Trust: 0.6

db:CS-HELPid:SB2022012639

Trust: 0.6

db:EXPLOIT-DBid:51193

Trust: 0.6

db:CNNVDid:CNNVD-202112-1579

Trust: 0.6

db:PACKETSTORMid:165745

Trust: 0.2

db:PACKETSTORMid:167186

Trust: 0.1

db:PACKETSTORMid:167188

Trust: 0.1

db:VULHUBid:VHN-408105

Trust: 0.1

db:VULMONid:CVE-2021-44790

Trust: 0.1

db:PACKETSTORMid:166581

Trust: 0.1

db:PACKETSTORMid:169211

Trust: 0.1

db:PACKETSTORMid:166051

Trust: 0.1

sources: CNVD: CNVD-2021-102386 // VULHUB: VHN-408105 // VULMON: CVE-2021-44790 // PACKETSTORM: 166583 // PACKETSTORM: 166581 // PACKETSTORM: 169211 // PACKETSTORM: 166051 // PACKETSTORM: 166154 // PACKETSTORM: 165710 // PACKETSTORM: 165745 // CNNVD: CNNVD-202112-1579 // NVD: CVE-2021-44790

REFERENCES

url:https://www.oracle.com/security-alerts/cpuapr2022.html

Trust: 2.4

url:https://www.debian.org/security/2022/dsa-5035

Trust: 1.9

url:https://nvd.nist.gov/vuln/detail/cve-2021-44790

Trust: 1.8

url:https://support.apple.com/kb/ht213255

Trust: 1.8

url:https://support.apple.com/kb/ht213256

Trust: 1.8

url:https://support.apple.com/kb/ht213257

Trust: 1.8

url:https://security.netapp.com/advisory/ntap-20211224-0001/

Trust: 1.8

url:https://www.tenable.com/security/tns-2022-01

Trust: 1.8

url:https://www.tenable.com/security/tns-2022-03

Trust: 1.8

url:http://seclists.org/fulldisclosure/2022/may/38

Trust: 1.8

url:http://seclists.org/fulldisclosure/2022/may/35

Trust: 1.8

url:http://seclists.org/fulldisclosure/2022/may/33

Trust: 1.8

url:https://security.gentoo.org/glsa/202208-20

Trust: 1.8

url:https://www.oracle.com/security-alerts/cpujan2022.html

Trust: 1.8

url:http://www.openwall.com/lists/oss-security/2021/12/20/4

Trust: 1.8

url:http://packetstormsecurity.com/files/171631/apache-2.4.x-buffer-overflow.html

Trust: 1.7

url:http://httpd.apache.org/security/vulnerabilities_24.html

Trust: 1.2

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/bfswoh4x77cv7ah7c4rmhubdwkqdl4yh/

Trust: 1.1

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/rgwilbort67shmslysqzg2nmxgcmpuzo/

Trust: 1.1

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/z7h26wj6tpknwv3qky4bhkukqvutzjtd/

Trust: 1.1

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/x73c35mmmzgbvpqqch7lqzumyznqa5fo/

Trust: 1.1

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/bfswoh4x77cv7ah7c4rmhubdwkqdl4yh/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/z7h26wj6tpknwv3qky4bhkukqvutzjtd/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/x73c35mmmzgbvpqqch7lqzumyznqa5fo/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/rgwilbort67shmslysqzg2nmxgcmpuzo/

Trust: 0.7

url:https://access.redhat.com/security/cve/cve-2021-44790

Trust: 0.6

url:https://listman.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.6

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.6

url:https://access.redhat.com/articles/11258

Trust: 0.6

url:https://bugzilla.redhat.com/):

Trust: 0.6

url:https://access.redhat.com/security/team/contact/

Trust: 0.6

url:httpd.apache.org/security/vulnerabilities_24.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0686

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022051316

Trust: 0.6

url:https://packetstormsecurity.com/files/166583/red-hat-security-advisory-2022-1137-01.html

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022010609

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022030119

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022042265

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0064

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022021427

Trust: 0.6

url:https://packetstormsecurity.com/files/165587/red-hat-security-advisory-2022-0143-03.html

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022060706

Trust: 0.6

url:https://packetstormsecurity.com/files/165710/red-hat-security-advisory-2022-0258-02.html

Trust: 0.6

url:https://packetstormsecurity.com/files/165501/ubuntu-security-notice-usn-5212-2.html

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022012517

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022012639

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0716

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0836

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.2352

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022010513

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0217

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.2411

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0039

Trust: 0.6

url:https://packetstormsecurity.com/files/168072/gentoo-linux-security-advisory-202208-20.html

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022012334

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0135

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0850

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0354

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022051703

Trust: 0.6

url:https://packetstormsecurity.com/files/165747/red-hat-security-advisory-2022-0303-02.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0396

Trust: 0.6

url:https://www.exploit-db.com/exploits/51193

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022011749

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.0171

Trust: 0.6

url:https://us-cert.cisa.gov/ics/advisories/icsa-22-132-02

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022060811

Trust: 0.6

url:https://vigilance.fr/vulnerability/apache-http-server-buffer-overflow-via-mod-lua-multipart-content-37112

Trust: 0.6

url:https://packetstormsecurity.com/files/166154/red-hat-security-advisory-2022-0682-01.html

Trust: 0.6

url:https://packetstormsecurity.com/files/165467/ubuntu-security-notice-usn-5212-1.html

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2021122021

Trust: 0.6

url:https://support.apple.com/en-us/ht213256

Trust: 0.6

url:https://packetstormsecurity.com/files/167189/apple-security-advisory-2022-05-16-4.html

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022012003

Trust: 0.6

url:https://access.redhat.com/security/team/key/

Trust: 0.4

url:https://access.redhat.com/errata/rhsa-2022:0288

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2022-22720

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-22720

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2022-24348

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/787.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://github.com/nupacachi/-cve-2021-44790

Trust: 0.1

url:https://www.cisa.gov/uscert/ics/advisories/icsa-22-132-02

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2022:1137

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2022:1139

Trust: 0.1

url:https://www.debian.org/security/faq

Trust: 0.1

url:https://www.debian.org/security/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-44224

Trust: 0.1

url:https://security-tracker.debian.org/tracker/apache2

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-14155

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-24370

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-13435

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-12762

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-20838

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-43527

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2022:0580

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3426

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-17594

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22876

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-17594

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-33574

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-33560

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-5827

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3800

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-33574

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-40346

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-42574

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-19603

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-27645

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-20231

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-24370

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-14145

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3572

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3445

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2016-4658

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22925

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3200

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-37750

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-22876

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-16135

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-13750

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-39241

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-17595

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22898

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-36085

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-28153

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-19603

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-13750

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-20271

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-20231

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3580

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-14155

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-16135

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-13751

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-17595

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-27645

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-22925

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-22898

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-36087

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-13751

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-3200

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-20271

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-20838

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-35942

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-12762

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-13435

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-36086

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3712

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2020-14145

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-28153

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-20232

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-33560

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-20232

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-18218

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2019-5827

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-36084

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-4658

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2019-18218

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3521

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2022:0682

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-24348

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2022:0258

Trust: 0.1

sources: CNVD: CNVD-2021-102386 // VULHUB: VHN-408105 // VULMON: CVE-2021-44790 // PACKETSTORM: 166583 // PACKETSTORM: 166581 // PACKETSTORM: 169211 // PACKETSTORM: 166051 // PACKETSTORM: 166154 // PACKETSTORM: 165710 // PACKETSTORM: 165745 // CNNVD: CNNVD-202112-1579 // NVD: CVE-2021-44790

CREDITS

Red Hat

Trust: 0.6

sources: PACKETSTORM: 166583 // PACKETSTORM: 166581 // PACKETSTORM: 166051 // PACKETSTORM: 166154 // PACKETSTORM: 165710 // PACKETSTORM: 165745

SOURCES

db:CNVDid:CNVD-2021-102386
db:VULHUBid:VHN-408105
db:VULMONid:CVE-2021-44790
db:PACKETSTORMid:166583
db:PACKETSTORMid:166581
db:PACKETSTORMid:169211
db:PACKETSTORMid:166051
db:PACKETSTORMid:166154
db:PACKETSTORMid:165710
db:PACKETSTORMid:165745
db:CNNVDid:CNNVD-202112-1579
db:NVDid:CVE-2021-44790

LAST UPDATE DATE

2025-04-28T22:01:06.937000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-102386date:2021-12-27T00:00:00
db:VULHUBid:VHN-408105date:2022-11-02T00:00:00
db:VULMONid:CVE-2021-44790date:2023-11-07T00:00:00
db:CNNVDid:CNNVD-202112-1579date:2023-04-04T00:00:00
db:NVDid:CVE-2021-44790date:2024-11-21T06:31:33.257

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-102386date:2021-12-24T00:00:00
db:VULHUBid:VHN-408105date:2021-12-20T00:00:00
db:VULMONid:CVE-2021-44790date:2021-12-20T00:00:00
db:PACKETSTORMid:166583date:2022-04-04T14:36:52
db:PACKETSTORMid:166581date:2022-04-04T14:36:10
db:PACKETSTORMid:169211date:2022-01-28T20:12:00
db:PACKETSTORMid:166051date:2022-02-18T16:37:39
db:PACKETSTORMid:166154date:2022-02-28T16:18:23
db:PACKETSTORMid:165710date:2022-01-26T15:06:30
db:PACKETSTORMid:165745date:2022-01-27T14:41:16
db:CNNVDid:CNNVD-202112-1579date:2021-12-20T00:00:00
db:NVDid:CVE-2021-44790date:2021-12-20T12:15:07.440