Описание
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie*
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A flaw was found in Apache HTTP Server. This heap-based buffer overflow vulnerability can be exploited by a malicious backend server when using ProxyPassReverseCookie* directives. This could lead to a denial of service (DoS) condition, making the server unavailable to legitimate users.
Отчет
This flaw in Apache could allow a malicious backend server to crash your web server, making it unavailable to users. Your system is only at risk if you use Apache to forward traffic to untrusted or unverified backend systems.
Меры по смягчению последствий
To prevent this denial-of-service flaw, ensure your Apache proxy rules only connect to highly trusted backend servers. If you must proxy traffic to unverified or external backends, disable the cookie-rewriting features. Steps to Mitigate: Open your Apache configuration file (e.g., /etc/httpd/conf/httpd.conf). Locate and comment out any ProxyPassReverseCookieDomain or ProxyPassReverseCookiePath lines pointing to untrusted backends by adding a # at the start of the line. Test your syntax: apachectl configtest Apply changes gracefully: systemctl reload httpd Note: This may cause a brief service interruption.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | httpd | Affected | ||
| Red Hat Enterprise Linux 7 | httpd | Affected | ||
| Red Hat Enterprise Linux 10 | httpd | Fixed | RHSA-2026:34109 | 01.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | httpd | Fixed | RHSA-2026:47046 | 28.07.2026 |
| Red Hat Enterprise Linux 8 | httpd | Fixed | RHSA-2026:42828 | 21.07.2026 |
| Red Hat Enterprise Linux 9 | httpd | Fixed | RHSA-2026:41906 | 20.07.2026 |
| Red Hat Hardened Images | httpd-main-2.4.68-1.hum1 | Fixed | RHSA-2026:25042 | 10.06.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with ma ...
7.5 High
CVSS3