Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:15095

Опубликовано: 03 окт. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: httpd security update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: insufficient escaping of user-supplied data in mod_ssl (CVE-2024-47252)

  • httpd: mod_ssl: access control bypass by trusted clients is possible using TLS 1.3 session resumption (CVE-2025-23048)

  • httpd: HTTP Session Hijack via a TLS upgrade (CVE-2025-49812)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
httpdx86_641.el10_0.2httpd-2.4.63-1.el10_0.2.x86_64.rpm
httpd-corex86_641.el10_0.2httpd-core-2.4.63-1.el10_0.2.x86_64.rpm
httpd-develx86_641.el10_0.2httpd-devel-2.4.63-1.el10_0.2.x86_64.rpm
httpd-filesystemnoarch1.el10_0.2httpd-filesystem-2.4.63-1.el10_0.2.noarch.rpm
httpd-manualnoarch1.el10_0.2httpd-manual-2.4.63-1.el10_0.2.noarch.rpm
httpd-toolsx86_641.el10_0.2httpd-tools-2.4.63-1.el10_0.2.x86_64.rpm
mod_ldapx86_641.el10_0.2mod_ldap-2.4.63-1.el10_0.2.x86_64.rpm
mod_luax86_641.el10_0.2mod_lua-2.4.63-1.el10_0.2.x86_64.rpm
mod_proxy_htmlx86_641.el10_0.2mod_proxy_html-2.4.63-1.el10_0.2.x86_64.rpm
mod_sessionx86_641.el10_0.2mod_session-2.4.63-1.el10_0.2.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
около 1 месяца назад

ELSA-2025-15095: httpd security update (MODERATE)

oracle-oval
около 1 месяца назад

ELSA-2025-15023: httpd security update (MODERATE)

oracle-oval
около 1 месяца назад

ELSA-2025-15123: httpd:2.4 security update (MODERATE)

suse-cvrf
2 месяца назад

Security update for apache2

suse-cvrf
2 месяца назад

Security update for apache2