Описание
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend.
Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A vulnerability has been identified in the Apache HTTP Server. If the server is configured to connect to a malicious or compromised backend server, an attacker could exploit this flaw to bypass security controls or run unauthorized code on the system.
Отчет
This Important vulnerability in mod_proxy_html within the Apache HTTP Server allows an untrusted backend to trigger a buffer overflow. This could lead to a security bypass or arbitrary code execution, posing a significant risk in environments where httpd is configured with untrusted backend services.
Меры по смягчению последствий
Disable the mod_proxy_html module if it is not essential for your Apache HTTP Server configuration. If mod_proxy_html is required, restrict its use to trusted backend servers only, employing network segmentation and access controls. After modifying the configuration, reload the httpd service for changes to apply, which may cause a brief service interruption.
Steps to disable:
Open /etc/httpd/conf.modules.d/00-proxy.conf.
Add a # to comment out the line: LoadModule proxy_html_module modules/mod_proxy_html.so
Verify configuration syntax: apachectl configtest
Apply the change gracefully: systemctl reload httpd
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | httpd | Affected | ||
| Red Hat Enterprise Linux 7 | httpd | Affected | ||
| Red Hat Enterprise Linux 8 | httpd | Affected | ||
| Red Hat Enterprise Linux 9 | httpd | Affected | ||
| Red Hat Hardened Images | httpd | Affected | ||
| Red Hat Enterprise Linux 10 | httpd | Fixed | RHSA-2026:34109 | 01.07.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and e ...
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
7.5 High
CVSS3