Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:23932

Опубликовано: 24 дек. 2025
Источник: rocky
Оценка: Important

Описание

Important: httpd security update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: Apache HTTP Server: CGI environment variable override (CVE-2025-65082)

  • httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (CVE-2025-66200)

  • httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (CVE-2025-58098)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
httpdx86_644.el10_1.3httpd-2.4.63-4.el10_1.3.x86_64.rpm
httpd-corex86_644.el10_1.3httpd-core-2.4.63-4.el10_1.3.x86_64.rpm
httpd-develx86_644.el10_1.3httpd-devel-2.4.63-4.el10_1.3.x86_64.rpm
httpd-filesystemnoarch4.el10_1.3httpd-filesystem-2.4.63-4.el10_1.3.noarch.rpm
httpd-filesystemnoarch4.el10_1.3httpd-filesystem-2.4.63-4.el10_1.3.noarch.rpm
httpd-filesystemnoarch4.el10_1.3httpd-filesystem-2.4.63-4.el10_1.3.noarch.rpm
httpd-filesystemnoarch4.el10_1.3httpd-filesystem-2.4.63-4.el10_1.3.noarch.rpm
httpd-manualnoarch4.el10_1.3httpd-manual-2.4.63-4.el10_1.3.noarch.rpm
httpd-manualnoarch4.el10_1.3httpd-manual-2.4.63-4.el10_1.3.noarch.rpm
httpd-manualnoarch4.el10_1.3httpd-manual-2.4.63-4.el10_1.3.noarch.rpm

Показывать по

Связанные уязвимости

rocky
около 1 месяца назад

Important: httpd security update

oracle-oval
около 2 месяцев назад

ELSA-2025-23932: httpd security update (IMPORTANT)

oracle-oval
около 2 месяцев назад

ELSA-2025-23919: httpd security update (IMPORTANT)

suse-cvrf
22 дня назад

Security update for apache2

suse-cvrf
около 1 месяца назад

Security update for apache2