Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-14983

Опубликовано: 01 сент. 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-14983: mod_http2 security update (MODERATE)

[2.0.26-4.1]

  • Resolves: RHEL-99956 - CVE-2025-49630 httpd: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

mod_http2

2.0.26-4.el9_6.1

Oracle Linux x86_64

mod_http2

2.0.26-4.el9_6.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".

CVSS3: 7.5
redhat
5 месяцев назад

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".

CVSS3: 7.5
nvd
5 месяцев назад

In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on".

CVSS3: 7.5
msrc
5 месяцев назад

Apache HTTP Server: mod_proxy_http2 denial of service

CVSS3: 7.5
debian
5 месяцев назад

In certain proxy configurations, a denial of service attack againstApa ...