Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:15123

Опубликовано: 08 сент. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: httpd:2.4 security update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: insufficient escaping of user-supplied data in mod_ssl (CVE-2024-47252)

  • httpd: mod_ssl: access control bypass by trusted clients is possible using TLS 1.3 session resumption (CVE-2025-23048)

  • httpd: mod_proxy_http2: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module (CVE-2025-49630)

  • httpd: HTTP Session Hijack via a TLS upgrade (CVE-2025-49812)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
httpdx86_6465.module+el8.10.0+1830+22f0c9e0httpd-2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm
httpdx86_6465.module+el8.10.0+1842+4a9649e8.2httpd-2.4.37-65.module+el8.10.0+1842+4a9649e8.2.x86_64.rpm
httpdx86_6465.module+el8.10.0+1984+1bed3124.4httpd-2.4.37-65.module+el8.10.0+1984+1bed3124.4.x86_64.rpm
httpdx86_6465.module+el8.10.0+1938+3b7755d4.3httpd-2.4.37-65.module+el8.10.0+1938+3b7755d4.3.x86_64.rpm
httpdx86_6465.module+el8.10.0+1840+b070a976.1httpd-2.4.37-65.module+el8.10.0+1840+b070a976.1.x86_64.rpm
httpd-develx86_6465.module+el8.10.0+1830+22f0c9e0httpd-devel-2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm
httpd-develx86_6465.module+el8.10.0+1840+b070a976.1httpd-devel-2.4.37-65.module+el8.10.0+1840+b070a976.1.x86_64.rpm
httpd-develx86_6465.module+el8.10.0+1984+1bed3124.4httpd-devel-2.4.37-65.module+el8.10.0+1984+1bed3124.4.x86_64.rpm
httpd-develx86_6465.module+el8.10.0+1842+4a9649e8.2httpd-devel-2.4.37-65.module+el8.10.0+1842+4a9649e8.2.x86_64.rpm
httpd-develx86_6465.module+el8.10.0+1938+3b7755d4.3httpd-devel-2.4.37-65.module+el8.10.0+1938+3b7755d4.3.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
4 месяца назад

ELSA-2025-15123: httpd:2.4 security update (MODERATE)

suse-cvrf
5 месяцев назад

Security update for apache2

suse-cvrf
5 месяцев назад

Security update for apache2

suse-cvrf
5 месяцев назад

Security update for apache2

suse-cvrf
5 месяцев назад

Security update for apache2