CVE-2021-41973: Apache MINA HTTP listener DOS

2021-11-01 Thread Emmanuel Lecharny
Severity: critical

Description:

In Apache MINA, a specifically crafted, malformed HTTP request may
cause the HTTP Header decoder to loop indefinitely.  The decoder
assumed that the HTTP Header begins at the beginning of the buffer and
loops if there is more data than expected.  Please update MINA to
2.1.5 or greater.

References:

https://lists.apache.org/thread.html/r0b907da9340d5ff4e6c1a4798ef4e79700a668657f27cca8a39e9250%40%3Cdev.mina.apache.org%3E



-- 
Regards,
Cordialement,
Emmanuel Lécharny
www.iktek.com


Apache Month in Review: October 2021

2021-11-01 Thread Sally Khudairi
[this post is available online at https://s.apache.org/October2021  ]

Welcome to the latest monthly overview of events from the Apache community. 
Here's a summary of what happened in October [video highlights available 
https://youtu.be/3rPR6tNt-dg ] :

New This Month --
- Apache Software Foundation moves to CDN distribution for software. 
https://s.apache.org/newuq
- The Apache Software Foundation Announces Apache® OpenOffice® 4.1.11 
https://s.apache.org/3x8kz 
- Presentations from ApacheCon 2021 events are available on the ASF's YouTube 
channel. https://s.apache.org/ASF-YouTube
- Apache Month in Review: September 2021 https://s.apache.org/September2021 

Important Dates --
- Next Board Meeting: 17 November 2021. Board calendar and minutes 
http://apache.org/foundation/board/calendar.html
- Apache CloudStack Collaboration Conference 2021 - 8-12 November 2021 
https://blogs.apache.org/foundation/entry/cloudstack-collaboration-conference-2021-november

Infrastructure --
Our seven-member Infrastructure team on three continents oversees our 
highly-reliable, distributed network under the leadership of VP Infrastructure 
David Nalley and Infrastructure Administrator Greg Stein. ASF Infrastructure 
supports 300+ Apache projects and their communities across ~200 individual 
machines, 1,400+ repositories, 5-6PB in traffic annually, ~75M downloads per 
month, and 2-3M daily emails on 2,000+ lists. ASF Infra performs 7M+ weekly 
checks to ensure services are available around the clock. The average uptime in 
October was 100.00%. http://www.apache.org/uptime/

Committer Activity --
In October, 643 Apache Committers changed 47,071,028 lines of code over 11,309 
commits. The Committers with the top 5 highest contributions, in order, were: 
Claus Ibsen, Andi Huber, Gary Gregory, Andrea Cosentino, and Alex Herbert.   

Project Releases and Updates --
New releases from Apache Airflow (Big Data); Ant (Build Management); APISIX 
(API); Bigtop (Big Data); Calcite (Big Data); Camel (Integration); CouchDB (Big 
Data); DB (Database); Flink (Big Data); Geode (Database); HBase (Big Data); Hop 
(Orchestration); HttpComponents (Servers); HTTP Server (Servers); Jackrabbit 
(Content); James (Mail); Kyuubi (Incubating; Big Data); Log4cxx (Libraries); 
Lucene (Search); OpenMeetings (Web Conferencing); OpenOffice (Content); PLC4X 
(IoT); Qpid (Messaging); ShardingSphere (Big Data); ShenYu (Incubating; API); 
SIS (Geospatial); Skywalking (Application Performance Management); Solr 
(Search); Storm (Big Data); Syncope (Identity Management);Tomcat (Servers); 
Traffic Control (Servers); XMLBeans (Library).

Apache Project Anniversaries in October: Apache Ant (19 years); HttpComponents 
(14 years); Attic, Buildr, CouchDB, and Qpid (13 years); Community Development 
("ComDev", 12 years); OODT and ZooKeeper (11 years); Kafka and Syncope (9 
years); Ambari (8 years); BookKeeper, Drill, and MetaModel (7 years); Brooklyn, 
Groovy, Kylin, and REEF (6 years); Geode (5 years); Guacamole, Impala, and 
Mnemonic (4 years); Griffin (3 years); Petri (2 years); and Superset and TVM (1 
year). Many happy returns! https://projects.apache.org/committees.html?date

The Apache Incubator is the primary entry path for projects wishing to become 
an official part of the ASF. More than three dozen projects are currently 
undergoing development in the Apache Incubator. http://incubator.apache.org/

# # #

To see our Weekly News Round-ups (published every Friday), visit 
https://blogs.apache.org/foundation/ and click on the calendar or hop directly 
to https://blogs.apache.org/foundation/category/Newsletter . For real-time 
updates, sign up for Apache-related news by sending mail to 
announce-subscr...@apache.org and follow @TheASF on Twitter. We appreciate your 
support!

= = =
NOTE: you are receiving this message because you are subscribed to the 
announce@apache.org distribution list. To unsubscribe, send email from the 
recipient account to announce-unsubscr...@apache.org with the word 
"Unsubscribe" in the subject line.


[ANNOUNCE] Apache MINA 2.0.22 & 2.1.5 released

2021-11-01 Thread Emmanuel Lecharny
The Apache MINA project is pleased to announce MINA 2.0.22 and 2.1.5 !


Apache MINA (http://mina.apache.org) is a network application
framework which helps users develop high performance and high
scalability network applications easily by providing an abstract,
event-driven, asynchronous API over various transports such as TCP/IP
and UDP/IP vis Java NIO.

The Apache MINA project website includes resources such as
introductory presentation slides, tutorials, and examples to help you
learn MINA as soon as possible.

This is a bug fix release for MINA 2.1.5 backported to MINA 2.0.22. it
fixes a CVE in the HTTP listener:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41973


Information relative to the API changes, and migration, are available
on the following page:
http://mina.apache.org/mina-project/2.1-vs-2.0.html


Downloads are available at
https://mina.apache.org/downloads-mina_2_1.html
https://mina.apache.org/downloads-mina_2_0.html

The Apache MINA PMC

Thanks !

--
Regards,
Cordialement,
Emmanuel Lécharny
www.iktek.com

-- 
Regards,
Cordialement,
Emmanuel Lécharny
www.iktek.com