ELA-567-1 apache2 security update

denial of service

2022-02-19
Packageapache2
Version2.4.10-10+deb8u20
Related CVEs CVE-2021-44224 CVE-2021-44790


Two vulnerabilities have been discovered in the Apache HTTP server:

CVE-2021-44224

When operating as a forward proxy, Apache was depending on the setup suspectable to denial of service or Server Side Request forgery.

CVE-2021-44790

A buffer overflow in mod_lua may result in denial of service or potentially the execution of arbitrary code.


For Debian 8 jessie, these problems have been fixed in version 2.4.10-10+deb8u20.

We recommend that you upgrade your apache2 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.