CVE-2022-29404

medium
Published 2022-11-15 Β· Modified 2022-11-18
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

Moderate: httpd security, bug fix, and enhancement update

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description httpd: mod_lua: DoS in r:parsebody Red Hat statement httpd as shipped with Red Hat Enterprise Linux 6, is not affected by this flaw because it does not ship mod_lua. CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8httpd:2.4-8070020220725152258.3b9f49c4RHSA-2022:76472022-11-08T00:00:00Z Red Hat…

Description

httpd: mod_lua: DoS in r:parsebody

Red Hat statement

httpd as shipped with Red Hat Enterprise Linux 6, is not affected by this flaw because it does not ship mod_lua.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8httpd:2.4-8070020220725152258.3b9f49c4RHSA-2022:76472022-11-08T00:00:00Z
Red Hat Enterprise Linux 9httpd-0:2.4.53-7.el9RHSA-2022:80672022-11-15T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7httpd24-httpd-0:2.4.34-23.el7.5RHSA-2022:67532022-09-29T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdOut of support scope
Red Hat JBoss Core Servicesjbcs-httpd24-httpdNot affected
Red Hat JBoss Enterprise Application Platform 6httpd22Out of support scope
Red Hat JBoss Web Server 3httpd24Will not fix

Apply commands

bash fix
Apply RHSA-2022:7647 for Red Hat Enterprise Linux 8
yum update -y httpd:2
# or:
dnf upgrade -y httpd:2

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat JBoss Core ServicesNot affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
9 Fixed httpd-manual-2.4.53-7.el9.noarch.rpm
arch Arch Fixed 1 release
VersionStatusFixed in
β€” Fixed 2.4.54-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.4.54-1
sid Fixed 2.4.54-1
forky Fixed 2.4.54-1
bullseye Fixed 2.4.54-1~deb11u1
bookworm Fixed 2.4.54-1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.