Bugzilla – Bug 1216424
VUL-0: CVE-2023-31122: apache2: Apache HTTP Server: mod_macro buffer over-read
Last modified: 2024-03-18 16:42:05 UTC
Severity: low Affected versions: - Apache HTTP Server through 2.4.57 Description: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57. Credit: David Shoon (github/davidshoon) (finder) References: https://httpd.apache.org/security/vulnerabilities_24.html https://httpd.apache.org/ https://www.cve.org/CVERecord?id=CVE-2023-31122 Timeline: 2023-04-04: Reported to security team
Based on the above advisory, tracking all codestreams as affected.
Upstream fix: - https://svn.apache.org/viewvc?view=revision&revision=1912993
SUSE-SU-2023:4432-1: An update that solves one vulnerability and has one security fix can now be installed. Category: security (important) Bug References: 1214357, 1216424 CVE References: CVE-2023-31122 Sources used: SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (src): apache2-2.4.33-150000.3.78.1 SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (src): apache2-2.4.33-150000.3.78.1 SUSE Linux Enterprise Server for SAP Applications 15 SP1 (src): apache2-2.4.33-150000.3.78.1 SUSE CaaS Platform 4.0 (src): apache2-2.4.33-150000.3.78.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:4431-1: An update that solves one vulnerability and has two security fixes can now be installed. Category: security (important) Bug References: 1207399, 1214357, 1216424 CVE References: CVE-2023-31122 Sources used: SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src): apache2-2.4.51-150200.3.59.1 SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (src): apache2-2.4.51-150200.3.59.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): apache2-2.4.51-150200.3.59.1 SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src): apache2-2.4.51-150200.3.59.1 SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): apache2-2.4.51-150200.3.59.1 SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src): apache2-2.4.51-150200.3.59.1 SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): apache2-2.4.51-150200.3.59.1 SUSE Manager Proxy 4.2 (src): apache2-2.4.51-150200.3.59.1 SUSE Manager Retail Branch Server 4.2 (src): apache2-2.4.51-150200.3.59.1 SUSE Manager Server 4.2 (src): apache2-2.4.51-150200.3.59.1 SUSE Enterprise Storage 7.1 (src): apache2-2.4.51-150200.3.59.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:4430-1: An update that solves one vulnerability and has two security fixes can now be installed. Category: security (important) Bug References: 1207399, 1214357, 1216424 CVE References: CVE-2023-31122 Sources used: openSUSE Leap 15.4 (src): apache2-2.4.51-150400.6.14.1 openSUSE Leap 15.5 (src): apache2-2.4.51-150400.6.14.1 Basesystem Module 15-SP4 (src): apache2-2.4.51-150400.6.14.1 Basesystem Module 15-SP5 (src): apache2-2.4.51-150400.6.14.1 SUSE Package Hub 15 15-SP4 (src): apache2-2.4.51-150400.6.14.1 SUSE Package Hub 15 15-SP5 (src): apache2-2.4.51-150400.6.14.1 Server Applications Module 15-SP4 (src): apache2-2.4.51-150400.6.14.1 Server Applications Module 15-SP5 (src): apache2-2.4.51-150400.6.14.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:4451-1: An update that solves one vulnerability and has two security fixes can now be installed. Category: security (important) Bug References: 1207399, 1214357, 1216424 CVE References: CVE-2023-31122 Sources used: SUSE Linux Enterprise Software Development Kit 12 SP5 (src): apache2-2.4.51-35.35.1, apache2-tls13-2.4.51-35.35.1 SUSE Linux Enterprise High Performance Computing 12 SP5 (src): apache2-2.4.51-35.35.1, apache2-tls13-2.4.51-35.35.1 SUSE Linux Enterprise Server 12 SP5 (src): apache2-2.4.51-35.35.1, apache2-tls13-2.4.51-35.35.1 SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): apache2-2.4.51-35.35.1, apache2-tls13-2.4.51-35.35.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.