oss-sec mailing list archives
Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow
From: Solar Designer <solar () openwall com>
Date: Fri, 7 Aug 2020 14:54:34 +0200
Hi Daniel, On Fri, Aug 07, 2020 at 06:31:38AM -0500, Daniel Ruggeri wrote:
CVE-2020-11984: mod_uwsgi buffer overlow Severity: moderate Vendor: The Apache Software Foundation Versions Affected: httpd 2.4.32 to 2.4.44 Description: Apache HTTP Server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE Mitigation: disable mod_uwsgi
You appear to use mod_uwsgi and mod_proxy_uwsgi interchangeably in the above, but I guess they're actually different modules?
Credit: Discovered by Felix Wilhelm of Google Project Zero References: https://httpd.apache.org/security/vulnerabilities_24.html
The vulnerability description at that link mentions mod_proxy_uwsgi only, so I guess it's the one affected module, whereas mod_uwsgi is unaffected? In general, I think you include too little detail in these postings and at the link above. You do include the bare minimum (thanks!), but it is unclear from these announcements where in the code the issues are. You could reference source files and function names and/or commits fixing the issues. You could also describe the impact in more detail - e.g., what kind of "info disclosure" (what info is potentially disclosed and to where). I am just using this as an example of how I think you could improve reporting on Apache httpd vulnerabilities in general. Thanks, Alexander
Current thread:
- CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Daniel Ruggeri (Aug 07)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Solar Designer (Aug 07)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Daniel Ruggeri (Aug 08)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Solar Designer (Aug 08)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Joe Orton (Aug 17)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Daniel Ruggeri (Aug 08)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Solar Designer (Aug 07)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Seth Arnold (Aug 07)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Daniel Ruggeri (Aug 08)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Seth Arnold (Aug 10)
- Re: CVE-2020-11984: Apache httpd: mod_uwsgi buffer overlow Daniel Ruggeri (Aug 08)