Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:1049

Опубликовано: 24 мар. 2022
Источник: rocky
Оценка: Important

Описание

Important: httpd:2.4 security update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling (CVE-2022-22720)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
httpdaarch6443.module+el8.5.0+714+5ec56ee8httpd-2.4.37-43.module+el8.5.0+714+5ec56ee8.aarch64.rpm
httpd-develaarch6443.module+el8.5.0+714+5ec56ee8httpd-devel-2.4.37-43.module+el8.5.0+714+5ec56ee8.aarch64.rpm
httpd-filesystemnoarch43.module+el8.5.0+714+5ec56ee8httpd-filesystem-2.4.37-43.module+el8.5.0+714+5ec56ee8.noarch.rpm
httpd-manualnoarch43.module+el8.5.0+714+5ec56ee8httpd-manual-2.4.37-43.module+el8.5.0+714+5ec56ee8.noarch.rpm
httpd-toolsaarch6443.module+el8.5.0+714+5ec56ee8httpd-tools-2.4.37-43.module+el8.5.0+714+5ec56ee8.aarch64.rpm
mod_http2aarch643.module+el8.4.0+553+7a69454bmod_http2-1.15.7-3.module+el8.4.0+553+7a69454b.aarch64.rpm
mod_http2aarch643.module+el8.5.0+695+1fa8055emod_http2-1.15.7-3.module+el8.5.0+695+1fa8055e.aarch64.rpm
mod_ldapaarch6443.module+el8.5.0+714+5ec56ee8mod_ldap-2.4.37-43.module+el8.5.0+714+5ec56ee8.aarch64.rpm
mod_mdaarch648.module+el8.5.0+695+1fa8055emod_md-2.0.8-8.module+el8.5.0+695+1fa8055e.aarch64.rpm
mod_mdaarch648.module+el8.4.0+553+7a69454bmod_md-2.0.8-8.module+el8.4.0+553+7a69454b.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 8.3
redhat
больше 4 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
nvd
больше 4 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
msrc
больше 4 лет назад

HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier

CVSS3: 9.8
debian
больше 4 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connectio ...