← Back to team overview

group.of.nepali.translators team mailing list archive

[Bug 2103723] Re: Fix for CVE-2024-38474 also blocks %3f in appended query strings

 

** Also affects: apache2 (Ubuntu Xenial)
   Importance: Undecided
       Status: New

** Also affects: apache2 (Ubuntu Bionic)
   Importance: Undecided
       Status: New

** Also affects: apache2 (Ubuntu Oracular)
   Importance: Undecided
       Status: New

** Also affects: apache2 (Ubuntu Noble)
   Importance: Undecided
       Status: New

** Also affects: apache2 (Ubuntu Jammy)
   Importance: Undecided
       Status: New

** Changed in: apache2 (Ubuntu Jammy)
       Status: New => Confirmed

** Changed in: apache2 (Ubuntu Noble)
       Status: New => Confirmed

** Changed in: apache2 (Ubuntu Oracular)
       Status: New => Confirmed

** Changed in: apache2 (Ubuntu Xenial)
     Assignee: (unassigned) => Leonidas S. Barbosa (leosilvab)

** Changed in: apache2 (Ubuntu Bionic)
     Assignee: (unassigned) => Leonidas S. Barbosa (leosilvab)

** Changed in: apache2 (Ubuntu Jammy)
     Assignee: (unassigned) => Leonidas S. Barbosa (leosilvab)

** Changed in: apache2 (Ubuntu Noble)
     Assignee: (unassigned) => Leonidas S. Barbosa (leosilvab)

** Changed in: apache2 (Ubuntu Oracular)
     Assignee: (unassigned) => Leonidas S. Barbosa (leosilvab)

** Changed in: apache2 (Ubuntu Xenial)
       Status: New => In Progress

** Changed in: apache2 (Ubuntu Bionic)
       Status: New => In Progress

** Changed in: apache2 (Ubuntu Noble)
       Status: Confirmed => In Progress

** Changed in: apache2 (Ubuntu Oracular)
       Status: Confirmed => In Progress

** Changed in: apache2 (Ubuntu Focal)
       Status: Confirmed => In Progress

** Changed in: apache2 (Ubuntu Jammy)
       Status: Confirmed => In Progress

-- 
You received this bug notification because you are a member of नेपाली
भाषा समायोजकहरुको समूह, which is subscribed to Xenial.
Matching subscriptions: Ubuntu 16.04 Bugs
https://bugs.launchpad.net/bugs/2103723

Title:
  Fix for CVE-2024-38474 also blocks %3f in appended query strings

Status in apache2 package in Ubuntu:
  Confirmed
Status in apache2 source package in Xenial:
  In Progress
Status in apache2 source package in Bionic:
  In Progress
Status in apache2 source package in Focal:
  In Progress
Status in apache2 source package in Jammy:
  In Progress
Status in apache2 source package in Noble:
  In Progress
Status in apache2 source package in Oracular:
  In Progress

Bug description:
  The fix introduced in
  https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.19

  "  * SECURITY UPDATE: Substitution encoding issue in mod_rewrite
      - debian/patches/CVE-2024-38474_5.patch: tighten up prefix_stat and %3f
        handling in modules/mappers/mod_rewrite.c.
      - CVE-2024-38474
  "

  is causing issues by being not specific enough and blocking lots of
  requests not exposed to the cve.

  It has already been fixed in apache2 2.4.63
  https://bz.apache.org/bugzilla/show_bug.cgi?id=69197
  "Bug 69197 - Fix for CVE-2024-38474 also blocks %3f in appended query strings"

  Please port the changes to the detection code from mainline apache2.

  Thank you

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/2103723/+subscriptions