Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:0970

Опубликовано: 06 апр. 2023
Источник: rocky
Оценка: Moderate

Описание

Moderate: httpd security and bug fix update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: mod_dav: out-of-bounds read/write of zero byte (CVE-2006-20001)

  • httpd: mod_proxy_ajp: Possible request smuggling (CVE-2022-36760)

  • httpd: mod_proxy: HTTP response splitting (CVE-2022-37436)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • httpd-init fails to create localhost.crt, localhost.key due to "sscg" default now creates a /dhparams.pem and is not idempotent if the file /dhparams.pem already exists. (BZ#2165975)

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
httpdx86_647.el9_1.1httpd-2.4.53-7.el9_1.1.x86_64.rpm
httpd-corex86_647.el9_1.1httpd-core-2.4.53-7.el9_1.1.x86_64.rpm
httpd-develx86_647.el9_1.1httpd-devel-2.4.53-7.el9_1.1.x86_64.rpm
httpd-filesystemnoarch7.el9_1.1httpd-filesystem-2.4.53-7.el9_1.1.noarch.rpm
httpd-manualnoarch7.el9_1.1httpd-manual-2.4.53-7.el9_1.1.noarch.rpm
httpd-toolsx86_647.el9_1.1httpd-tools-2.4.53-7.el9_1.1.x86_64.rpm
mod_ldapx86_647.el9_1.1mod_ldap-2.4.53-7.el9_1.1.x86_64.rpm
mod_luax86_647.el9_1.1mod_lua-2.4.53-7.el9_1.1.x86_64.rpm
mod_proxy_htmlx86_647.el9_1.1mod_proxy_html-2.4.53-7.el9_1.1.x86_64.rpm
mod_sessionx86_647.el9_1.1mod_session-2.4.53-7.el9_1.1.x86_64.rpm

Показывать по

Связанные уязвимости

suse-cvrf
больше 2 лет назад

Security update for apache2

suse-cvrf
больше 2 лет назад

Security update for apache2

suse-cvrf
больше 2 лет назад

Security update for apache2

suse-cvrf
больше 2 лет назад

Security update for apache2

suse-cvrf
больше 2 лет назад

Security update for apache2