Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-1809

Опубликовано: 25 мая 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-1809: httpd:2.4 security, bug fix, and enhancement update (MODERATE)

httpd [2.4.37-39.0.1]

  • Set vstring per ORACLE_SUPPORT_PRODUCT [Orabug: 29892262]
  • Replace index.html with Oracles index page oracle_index.html

[2.4.37-39]

  • prevent htcacheclean from while break when first file processed

[2.4.37-38]

  • Resolves: #1918741 - Thousands of /tmp/modproxy.tmp.* files created by apache

[2.4.37-37]

  • Resolves: #1883648 - [RFE] Update httpd directive SSLProxyMachineCertificateFile to be able to handle certs without matching private key

[2.4.37-36]

  • Resolves: #1896176 - [RFE] ProxyWebsocketIdleTimeout from httpd mod_proxy_wstunnel
  • Resolves: #1847585 - mod_ldap: High CPU usage at apr_ldap_rebind_remove()

[2.4.37-35]

  • Resolves: #1651376 - centralizing default index.html for httpd

[2.4.37-33]

  • Resolves: #1868608 - Intermittent Segfault in Apache httpd due to pool concurrency issues
  • Resolves: #1861380 - httpd/mod_proxy_http/mod_ssl aborted when sending a client cert to backend server
  • Resolves: #1680118 - unorderly connection close when client attempts renegotiation

[2.4.37-31]

  • Resolves: #1677590 - CVE-2018-17199 httpd:2.4/httpd: mod_session_cookie does not respect expiry time
  • Resolves: #1869075 - CVE-2020-11984 httpd:2.4/httpd: mod_proxy_uswgi buffer overflow
  • Resolves: #1872828 - httpd: typo in htpasswd, contained in httpd-tools package
  • Resolves: #1869576 - httpd : mod_proxy should allow to specify Proxy-Authorization in ProxyRemote directive
  • Resolves: #1875844 - mod_cgid takes CGIDScriptTimeout x 2 seconds for timeout
  • Resolves: #1891829 - mod_proxy_hcheck Doesnt perform checks when in a balancer

mod_http2 [1.15.7-3]

  • Resolves: #1869077 - CVE-2020-11993 httpd:2.4/mod_http2: httpd: mod_http2 concurrent pool usage

mod_md [1:2.0.8-8]

  • Resolves: #1832844 - mod_md does not work with ACME server that does not provide keyChange or revokeCert resources

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module httpd:2.4 is enabled

mod_http2

1.15.7-3.module+el8.4.0+20024+b87b2deb

mod_md

2.0.8-8.module+el8.3.0+7816+49791cfd

httpd

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

httpd-devel

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

httpd-filesystem

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

httpd-manual

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

httpd-tools

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

mod_ldap

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

mod_proxy_html

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

mod_session

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

mod_ssl

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

Oracle Linux x86_64

Module httpd:2.4 is enabled

mod_http2

1.15.7-3.module+el8.4.0+20024+b87b2deb

mod_md

2.0.8-8.module+el8.3.0+7816+49791cfd

httpd

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

httpd-devel

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

httpd-filesystem

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

httpd-manual

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

httpd-tools

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

mod_ldap

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

mod_proxy_html

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

mod_session

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

mod_ssl

2.4.37-39.0.1.module+el8.4.0+20024+b87b2deb

Связанные уязвимости

rocky
около 4 лет назад

Moderate: httpd:2.4 security, bug fix, and enhancement update

suse-cvrf
почти 5 лет назад

Security update for apache2

suse-cvrf
почти 5 лет назад

Security update for apache2

suse-cvrf
почти 5 лет назад

Security update for apache2

suse-cvrf
почти 5 лет назад

Security update for apache2