imPC@ndo IT

Tracker / CVE-2021-44790

CVE-2021-44790

Critical 9.8

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

Affected products and versions

apache http_server · … → 2.4.52
apple mac_os_x
apple macos · … → 10.15.7
apple macos · 11.0 → 11.6.6
apple macos · 12.0 → 12.4
debian debian_linux
fedoraproject fedora
netapp cloud_backup
oracle communications_element_manager · … → 9.0
oracle communications_operations_monitor
oracle communications_session_report_manager · … → 9.0
oracle communications_session_route_manager · … → 9.0
oracle http_server
oracle instantis_enterprisetrack
oracle zfs_storage_appliance_kit
tenable tenable.sc · 5.16.0 → 5.20.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References