← Back to team overview

group.of.nepali.translators team mailing list archive

[Bug 2103723] Re: Fix for CVE-2024-38474 also blocks %3f in appended query strings

 

This bug was fixed in the package apache2 - 2.4.62-1ubuntu1.1

---------------
apache2 (2.4.62-1ubuntu1.1) oracular-security; urgency=medium

  * SECURITY REGRESSION: Better question mark tracking
    - debian/patches/CVE-2024-38474-regression.patch: improve
      previous patch allowing to avoid [UnsafeAllow3F] for most
      cases in modules/mappers/mod_rewrite.c (LP: #2103723).

 -- Leonidas Da Silva Barbosa <leo.barbosa@xxxxxxxxxxxxx>  Thu, 03 Apr
2025 06:16:23 -0300

** Changed in: apache2 (Ubuntu Oracular)
       Status: In Progress => Fix Released

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2024-38474

** Changed in: apache2 (Ubuntu Jammy)
       Status: In Progress => Fix Released

-- 
You received this bug notification because you are a member of नेपाली
भाषा समायोजकहरुको समूह, which is subscribed to Xenial.
Matching subscriptions: Ubuntu 16.04 Bugs
https://bugs.launchpad.net/bugs/2103723

Title:
  Fix for CVE-2024-38474 also blocks %3f in appended query strings

Status in apache2 package in Ubuntu:
  Confirmed
Status in apache2 source package in Xenial:
  In Progress
Status in apache2 source package in Bionic:
  In Progress
Status in apache2 source package in Focal:
  Fix Released
Status in apache2 source package in Jammy:
  Fix Released
Status in apache2 source package in Noble:
  In Progress
Status in apache2 source package in Oracular:
  Fix Released

Bug description:
  The fix introduced in
  https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.19

  "  * SECURITY UPDATE: Substitution encoding issue in mod_rewrite
      - debian/patches/CVE-2024-38474_5.patch: tighten up prefix_stat and %3f
        handling in modules/mappers/mod_rewrite.c.
      - CVE-2024-38474
  "

  is causing issues by being not specific enough and blocking lots of
  requests not exposed to the cve.

  It has already been fixed in apache2 2.4.63
  https://bz.apache.org/bugzilla/show_bug.cgi?id=69197
  "Bug 69197 - Fix for CVE-2024-38474 also blocks %3f in appended query strings"

  Please port the changes to the detection code from mainline apache2.

  Thank you

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/2103723/+subscriptions