Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 736282 (CVE-2020-11984, CVE-2020-11985, CVE-2020-11993, CVE-2020-9490) - <www-servers/apache-2.4.46: Multiple vulnerabilities (CVE-2020-{9490,11993,11984,11985})
Summary: <www-servers/apache-2.4.46: Multiple vulnerabilities (CVE-2020-{9490,11993,11...
Status: RESOLVED FIXED
Alias: CVE-2020-11984, CVE-2020-11985, CVE-2020-11993, CVE-2020-9490
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major
Assignee: Gentoo Security
URL:
Whiteboard: B1 [glsa+ cve]
Keywords: CC-ARCHES, STABLEREQ
Depends on:
Blocks:
 
Reported: 2020-08-07 18:33 UTC by Sam James
Modified: 2020-08-31 23:27 UTC (History)
3 users (show)

See Also:
Package list:
www-servers/apache-2.4.46 app-admin/apache-tools-2.4.46
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-07 18:33:09 UTC
* CVE-2020-11993

Description:
"Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers."

* CVE-2020-11984

Description:
"Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE"

* CVE-2020-11985

Description:
"IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low severity CVE in 2020."
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-07 19:25:24 UTC
* CVE-2020-9490

Description:
"A specially crafted value for the 'Cache-Digest' header in a HTTP/2
request would result in a crash when the server actually tries to HTTP/2
PUSH a resource afterwards.

Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers."
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-08 00:26:24 UTC
arm done
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-08 01:28:55 UTC
sparc done
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-08 03:50:01 UTC
x86 done
Comment 5 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-08 03:53:53 UTC
arm64 done
Comment 6 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-08 03:55:14 UTC
amd64 done
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2020-08-08 04:24:41 UTC
This issue was resolved and addressed in
 GLSA 202008-04 at https://security.gentoo.org/glsa/202008-04
by GLSA coordinator Sam James (sam_c).
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-08 04:25:55 UTC
Reopening for remaining arches.
Comment 9 Sergei Trofimovich (RETIRED) gentoo-dev 2020-08-09 17:03:48 UTC
hppa stable
Comment 10 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-29 18:19:10 UTC
ppc done
Comment 11 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-08-31 22:58:49 UTC
ppc64 done

all arches done
Comment 12 Larry the Git Cow gentoo-dev 2020-08-31 23:00:33 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=fdc63e39dd1365d45aaf16389ca3ba746a6eae09

commit fdc63e39dd1365d45aaf16389ca3ba746a6eae09
Author:     Thomas Deutschmann <whissi@gentoo.org>
AuthorDate: 2020-08-31 23:00:21 +0000
Commit:     Thomas Deutschmann <whissi@gentoo.org>
CommitDate: 2020-08-31 23:00:28 +0000

    www-servers/apache: security cleanup
    
    Bug: https://bugs.gentoo.org/736282
    Package-Manager: Portage-3.0.4, Repoman-3.0.1
    Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>

 www-servers/apache/Manifest             |   1 -
 www-servers/apache/apache-2.4.43.ebuild | 272 --------------------------------
 2 files changed, 273 deletions(-)