Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-4537

Опубликовано: 18 нояб. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-4537: httpd:2.4 security update (IMPORTANT)

httpd [2.4.37-43.0.1]

  • Set vstring per ORACLE_SUPPORT_PRODUCT [Orabug: 29892262]
  • Replace index.html with Oracle's index page oracle_index.html.

[2.4.37-43]

  • Related: #2007235 - CVE-2021-40438 httpd:2.4/httpd: mod_proxy: SSRF via a crafted request uri-path

[2.4.37-42]

  • Resolves: #2007235 - CVE-2021-40438 httpd:2.4/httpd: mod_proxy: SSRF via a crafted request uri-path
  • Resolves: #2014063 - CVE-2021-26691 httpd:2.4/httpd: Heap overflow in mod_session

[2.4.37-41]

  • Resolves: #1680111 - httpd sends reply to HTTPS GET using two TLS records
  • Resolves: #1905613 - mod_ssl does not like valid certificate chain
  • Resolves: #1935742 - [RFE] backport samesite/httponly/secure flags for usertrack
  • Resolves: #1972500 - CVE-2021-30641 httpd:2.4/httpd: MergeSlashes regression
  • Resolves: #1968307 - CVE-2021-26690 httpd:2.4/httpd: mod_session NULL pointer dereference in parser
  • Resolves: #1934741 - Apache trademark update - new logo

[2.4.37-40]

  • Resolves: #1952557 - mod_proxy_wstunnel.html is a malformed XML
  • Resolves: #1937334 - SSLProtocol with based virtual hosts

mod_http2 [1.15.7-3]

  • Resolves: #1869077 - CVE-2020-11993 httpd:2.4/mod_http2: httpd: mod_http2 concurrent pool usage

mod_md [1:2.0.8-8]

  • Resolves: #1832844 - mod_md does not work with ACME server that does not provide keyChange or revokeCert resources

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module httpd:2.4 is enabled

httpd

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

httpd-devel

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

httpd-filesystem

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

httpd-manual

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

httpd-tools

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

mod_http2

1.15.7-3.module+el8.4.0+20024+b87b2deb

mod_ldap

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

mod_md

2.0.8-8.module+el8.3.0+7816+49791cfd

mod_proxy_html

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

mod_session

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

mod_ssl

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

Oracle Linux x86_64

Module httpd:2.4 is enabled

httpd

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

httpd-devel

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

httpd-filesystem

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

httpd-manual

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

httpd-tools

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

mod_http2

1.15.7-3.module+el8.4.0+20024+b87b2deb

mod_ldap

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

mod_md

2.0.8-8.module+el8.3.0+7816+49791cfd

mod_proxy_html

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

mod_session

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

mod_ssl

2.4.37-43.0.1.module+el8.5.0+20426+404a9eb9

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.

CVSS3: 9
redhat
больше 3 лет назад

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.

CVSS3: 9.8
nvd
больше 3 лет назад

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.

CVSS3: 9.8
debian
больше 3 лет назад

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of ...

rocky
больше 3 лет назад

Important: httpd:2.4 security update