group.of.nepali.translators team mailing list archive
  
  - 
     group.of.nepali.translators team group.of.nepali.translators team
- 
    Mailing list archive
  
- 
    Message #49116
  
 [Bug 2103723] Re: Fix for	CVE-2024-38474 also blocks %3f in appended query strings
  
This bug was fixed in the package apache2 - 2.4.52-1ubuntu4.14
---------------
apache2 (2.4.52-1ubuntu4.14) jammy-security; urgency=medium
  * SECURITY REGRESSION: Better question mark tracking
    - debian/patches/CVE-2024-38474-regression.patch: improve
      previous patch allowing to avoid [UnsafeAllow3F] for most
      cases in modules/mappers/mod_rewrite.c (LP: #2103723).
 -- Leonidas Da Silva Barbosa <leo.barbosa@xxxxxxxxxxxxx>  Thu, 03 Apr
2025 06:05:48 -0300
** Changed in: apache2 (Ubuntu Focal)
       Status: In Progress => Fix Released
-- 
You received this bug notification because you are a member of नेपाली
भाषा समायोजकहरुको समूह, which is subscribed to Xenial.
Matching subscriptions: Ubuntu 16.04 Bugs
https://bugs.launchpad.net/bugs/2103723
Title:
  Fix for CVE-2024-38474 also blocks %3f in appended query strings
Status in apache2 package in Ubuntu:
  Confirmed
Status in apache2 source package in Xenial:
  In Progress
Status in apache2 source package in Bionic:
  In Progress
Status in apache2 source package in Focal:
  Fix Released
Status in apache2 source package in Jammy:
  Fix Released
Status in apache2 source package in Noble:
  In Progress
Status in apache2 source package in Oracular:
  Fix Released
Bug description:
  The fix introduced in
  https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.19
  "  * SECURITY UPDATE: Substitution encoding issue in mod_rewrite
      - debian/patches/CVE-2024-38474_5.patch: tighten up prefix_stat and %3f
        handling in modules/mappers/mod_rewrite.c.
      - CVE-2024-38474
  "
  is causing issues by being not specific enough and blocking lots of
  requests not exposed to the cve.
  It has already been fixed in apache2 2.4.63
  https://bz.apache.org/bugzilla/show_bug.cgi?id=69197
  "Bug 69197 - Fix for CVE-2024-38474 also blocks %3f in appended query strings"
  Please port the changes to the detection code from mainline apache2.
  Thank you
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/2103723/+subscriptions