Vulnerability Description
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | < 2.4.52 |
| Fedoraproject | Fedora | 34 |
| Debian | Debian Linux | 10.0 |
| Tenable | Tenable.Sc | >= 5.16.0, < 5.20.0 |
| Netapp | Cloud Backup | - |
| Oracle | Communications Element Manager | <= 9.0 |
| Oracle | Communications Operations Monitor | 4.3 |
| Oracle | Communications Session Report Manager | <= 9.0 |
| Oracle | Communications Session Route Manager | <= 9.0 |
| Oracle | Http Server | 12.2.1.3.0 |
| Oracle | Instantis Enterprisetrack | 17.1 |
| Oracle | Zfs Storage Appliance Kit | 8.8 |
| Apple | Mac Os X | 10.15.7 |
| Apple | Macos | < 10.15.7 |
Related Weaknesses (CWE)
References
- http://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- http://packetstormsecurity.com/files/171631/Apache-2.4.x-Buffer-Overflow.htmlExploit
- http://seclists.org/fulldisclosure/2022/May/33Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/35Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2022/May/38Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/20/4Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproThird Party Advisory
- https://security.gentoo.org/glsa/202208-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211224-0001/Third Party Advisory
- https://support.apple.com/kb/HT213255Third Party Advisory
- https://support.apple.com/kb/HT213256Third Party Advisory
- https://support.apple.com/kb/HT213257Third Party Advisory
FAQ
What is CVE-2021-44790?
CVE-2021-44790 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabi...
How severe is CVE-2021-44790?
CVE-2021-44790 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-44790?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Fedoraproject Fedora, Debian Debian Linux, Tenable Tenable.Sc, Netapp Cloud Backup.