Bug 65944 - Does VE-2021-40438 also affects Apache httpd 2.2.x versions.
Summary: Does VE-2021-40438 also affects Apache httpd 2.2.x versions.
Status: RESOLVED WONTFIX
Alias: None
Product: Apache httpd-2
Classification: Unclassified
Component: mod_proxy (show other bugs)
Version: 2.4.52
Hardware: PC Linux
: P2 normal (vote)
Target Milestone: ---
Assignee: Apache HTTPD Bugs Mailing List
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-03-09 11:12 UTC by Stefan
Modified: 2022-03-15 13:06 UTC (History)
0 users



Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan 2022-03-09 11:12:13 UTC
Hi,

In the description of VE-2021-40438 it says that it affects Apache HTTP Server 2.4.48 and earlier.

Does this apply only for 2.4.x versions, and could you confirm if Apache 2.2.x versions are not affected by this vulnerability.

Regards,
Stefan
Comment 1 Stefan Eissing 2022-03-09 11:57:42 UTC
Apache 2.2 has been End-Of-Life since January 2018. That means the project no longer offers free support for that version.

We recommend upgrading to the latest 2.4.x release.

Kind Regards,
Stefan
Comment 2 Stefan 2022-03-14 08:08:55 UTC
Hi Stefan,

Actually my request was not for fixing the Apache 2.2.x version, but I just want to understand if those versions are also vulnerable.

Therefore could you please confirm if Apache 2.2.x is, or is not affected by VE-2021-40438 vulnerability.

Regards,
Stefan
Comment 3 Stefan Eissing 2022-03-14 09:41:47 UTC
If you run httpd 2.2 in an environment where CVEs are a concern, you have more important problems than this CVE.
Comment 4 Ruediger Pluem 2022-03-15 13:06:21 UTC
Just to be clear: Any security issue that has been reported for Apache HTTP server after 2.2 was EOL was not checked by this project whether it affects any version of 2.2. There might be other distributors of Apache 2.2 (commercial products, LTS OS distributions) that still do this / did this for some time. You might find hints there. But using any vanilla 2.2 version is strongly discouraged for security reasons.