Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in http-parser
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in http-parser
ID: USN-5563-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS
Datum: Do, 11. August 2022, 07:00
Referenzen: http-parser vulnerability
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8287
http-parser could be made to expose sensitive data if it received
Applikationen: http-parser

Originalnachricht


--===============8834938745825121312==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="FCuugMFkClbJLl1L"
Content-Disposition: inline


--FCuugMFkClbJLl1L
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-5563-1
August 10, 2022

http-parser vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

http-parser could be made to expose sensitive data if it received
a specially crafted request.

Software Description:
- http-parser: parser for HTTP messages: development libraries and header files

Details:

It was discovered that http-parser incorrectly handled certain requests.
An attacker could possibly use this issue to bypass security controls or
gain unauthorized access to sensitive data.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
libhttp-parser2.7.1 2.7.1-2ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5563-1
CVE-2020-8287

Package Information:
https://launchpad.net/ubuntu/+source/http-parser/2.7.1-2ubuntu0.1

--FCuugMFkClbJLl1L
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAmLz92IACgkQRbznW4QL
H2lahA/8DYERLz09qX2UPyFnbdhPdzUCMYpudj4NNgRYb8Rk8BNw3x4lL5arSFO0
RagRzv5yQ1i7wXSNlQTWbwXM5oNuLi9tSTSOy2OVGY6bFPOzTr2USiKKjdFZ3RhY
vDJUTUrEayLggHafjoBM/8WltDRXMQhhaOarTH1T51fDAP96xhngPL0he6Z0/6RG
0kZpVLZY6cR6RfZ9XVIVDygWpawWZyIHSdJQkU0yaPYOeOpAVxaVsWRlJ+wnjj1h
+5A41eM+QFBRcYyV/4OxfcvIOHr9UYebdvhKhGaOT4c+dNqW1klhdqj5yPSb72Gi
JnD/hFVUEbsRbDZidK72Oa/3svBveHe6U5rvv46+CjLQ0lN8w3NPnFiK65/Zwief
GCe9Hy7cte4gJnq64u93ecnNJ7OPIKjZcxr18cfvj0h8LUBTKKdMHSYy23Di5vDc
0MUQKOhcZTPZEBO2HMT9GYJzMTNBddzpmg4xQVapGC6TEzotjxU+BTPcbHKP8w7Z
jYjcrMG6nvaogmhZHRh3JtqtvcAAFuxTQLicG22JeYfihI4Tx6pKfRb2YLRorzIA
YamDmLQTbWj3Mrvpdtc2/GVuuNEUzNW8vgBRjW6dxSp+iyEvTRY6GR7aiuk0Kvz6
ir54IvybzDNNlv94Gj3QgNnDu5liSIAiGbpMn7EVaNRZCoGlqeQ=
=9ukA
-----END PGP SIGNATURE-----

--FCuugMFkClbJLl1L--


--===============8834938745825121312==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline


--===============8834938745825121312==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung