VDB
BDU%3A2022-05817
BDU%3A2022-05817
PUBLISHED
CVSS 7.5 HIGH
Уязвимость демона HTTP-сервера HTTP Daemon, связанная с непоследовательной интерпритацией HTTP-запросов, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 2.0
7.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Novell Inc., ООО «Ред Софт», АО «ИВК», Сообщество свободного программного обеспечения, АО "НППКТ" | Ubuntu, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, openSUSE Tumbleweed, SUSE Linux Enterprise Module for Basesystem, OpenSUSE Leap, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise High Performance Computing, SUSE Manager Proxy, SUSE Manager Server, Suse Linux Enterprise Desktop, Альт 8 СП (запись в едином реестре российских программ №4305), SUSE Manager Retail Branch Server, SUSE Enterprise Storage, HTTP Daemon, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913) |
Timeline
- Sep 21, 2022 CVE Published
- Aug 27, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- http://metacpan.org/release/HTTP-Daemon/ url
- https://cwe.mitre.org/data/definitions/444.html url
- https://datatracker.ietf.org/doc/html/rfc7230#section-9.5 url
- https://github.com/libwww-perl/HTTP-Daemon/commit/8dc5269d59e2d5d9eb1647d82c449ccd880f7fd0 url
- https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn url
- https://nvd.nist.gov/vuln/detail/CVE-2022-31081 url
- https://ubuntu.com/security/notices/USN-5520-2 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.6/ url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://github.com/libwww-perl/HTTP-Daemon/commit/e84475de51d6fd7b29354a997413472a99db70b2 advisory
- https://github.com/libwww-perl/HTTP-Daemon/security/advisories/GHSA-cg8c-pxmv-w7cf advisory
- https://www.suse.com/security/cve/CVE-2022-31081.html advisory
- https://ubuntu.com/security/notices/USN-5520-1 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory