Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-60004-0

Опубликовано: 26 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-60004-0: httpd security update (LOW)

[2.4.63-13.0.1.el10_2.6]

  • Replace index.html with Oracle's index page oracle_index.html.

[2.4.63-13.6]

  • Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration (CVE-2026-29167)

[2.4.63-13.5]

  • Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

[2.4.63-13.4]

  • Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
  • Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
  • Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
  • Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
  • Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
  • Resolves : RHEL-182581 - httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
  • Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
  • Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535, CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

[2.4.63-13.1]

  • Resolves: RHEL-173549 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780)
  • Resolves: RHEL-175065 - httpd: NULL pointer dereference can cause a child process crash (CVE-2026-33007)
  • Resolves: RHEL-175095 - httpd: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857)
  • Resolves: RHEL-175039 - httpd: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032)
  • Resolves: RHEL-175050 - httpd: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

httpd

2.4.63-13.0.1.el10_2.6

httpd-core

2.4.63-13.0.1.el10_2.6

httpd-devel

2.4.63-13.0.1.el10_2.6

httpd-filesystem

2.4.63-13.0.1.el10_2.6

httpd-manual

2.4.63-13.0.1.el10_2.6

httpd-tools

2.4.63-13.0.1.el10_2.6

mod_ldap

2.4.63-13.0.1.el10_2.6

mod_lua

2.4.63-13.0.1.el10_2.6

mod_proxy_html

2.4.63-13.0.1.el10_2.6

mod_session

2.4.63-13.0.1.el10_2.6

mod_ssl

2.4.63-13.0.1.el10_2.6

Oracle Linux x86_64

httpd

2.4.63-13.0.1.el10_2.6

httpd-core

2.4.63-13.0.1.el10_2.6

httpd-devel

2.4.63-13.0.1.el10_2.6

httpd-filesystem

2.4.63-13.0.1.el10_2.6

httpd-manual

2.4.63-13.0.1.el10_2.6

httpd-tools

2.4.63-13.0.1.el10_2.6

mod_ldap

2.4.63-13.0.1.el10_2.6

mod_lua

2.4.63-13.0.1.el10_2.6

mod_proxy_html

2.4.63-13.0.1.el10_2.6

mod_session

2.4.63-13.0.1.el10_2.6

mod_ssl

2.4.63-13.0.1.el10_2.6

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 4.6
redhat
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 9.8
nvd
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

msrc
3 месяца назад

Apache HTTP Server: mod_ldap per-dir use-after-free

CVSS3: 9.8
debian
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in pe ...