Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-42535

Опубликовано: 08 июн. 2026
Источник: debian

Описание

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.68-1package
apache2fixed2.4.68-1~deb13u1trixiepackage
apache2fixed2.4.68-1~deb12u1bookwormpackage

Примечания

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42535

  • Fixed by: https://github.com/apache/httpd/commit/7e871beec56d41fe098f48f5a5bcb1525c448d77 (trunk)

  • Fixed by: https://github.com/apache/httpd/commit/56bfb128432a38e2e6bc5448122914bb271b1252 (2.4.68-rc1-candidate)

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 2 месяцев назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

CVSS3: 6.5
redhat
около 2 месяцев назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

CVSS3: 9.1
nvd
около 2 месяцев назад

A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

msrc
около 2 месяцев назад

Apache HTTP Server: mod_dav_fs protected directory access

CVSS3: 9.1
redos
4 дня назад

Уязвимость httpd