possible vuln to patch in Apache HTTP Server? (version 2.4.51 and earlier)

mmerlin

Verified User
Joined
Jul 26, 2004
Messages
76
Location
Melbourne, Australia
Hi, are these two new vulnerabilities of any concern for plain vanilla installs of standard DA? (Apache+NGINX for httpd)


CVE-2021-44790: Possible buffer overflow when parsing a carefully crafted request in the mod_lua multipart parser of Apache HTTP Server 2.4.51 and earlier.

CVE-2021-44224: Possible NULL dereference or Server Side Request Forgery (SSRF) in forward proxy configurations
 
Hi, are these two new vulnerabilities of any concern for plain vanilla installs of standard DA? (Apache+NGINX for httpd)
Please be careful with updates while to many problems ....?


No answer but @DirectAdmin Support take care of the "many" httpd problems please?

 
Please be careful with updates while to many problems ....?
Some do have issues, some don't. I also don't have issues. People with issues can easily revert. And at this moment people need to use the custom setting to upgrade to 2.4.52.

You can read in the other thread that DA does not use mod_lua by default.
 
You can read in the other thread that DA does not use mod_lua by default.

Ah ha thanks!

Good to know we are not vuln by default

 
Back
Top