[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253164

 
 

909

 
 

197077

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2018:3558-01 -- Redhat httpd24-curl, httpd24-httpd, httpd24-nghttp2

ID: oval:org.secpod.oval:def:505099Date: (C)2021-01-29   (M)2024-01-29
Class: PATCHFamily: unix




The Apache HTTP Server is a powerful, efficient, and extensible web server. The httpd24 packages provide a recent stable release of version 2.4 of the Apache HTTP Server, along with the mod_auth_kerb module. The following packages have been upgraded to a later upstream version: httpd24-httpd , httpd24-curl . Security Fix: * httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications * httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS * httpd: mod_http2: Too much time allocated to workers, possibly leading to DoS * httpd: DoS for HTTP/2 connections by continuous SETTINGS frames * httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values * httpd: FilesMatch bypass with a trailing newline in the file name * httpd: Out of bounds access after failure in reading the HTTP request * httpd: Weak Digest auth nonce generation in mod_auth_digest * curl: Multiple security issues were fixed in httpd24-curl For more details about the security issue, including the impact, a CVSS score, and other related information, refer to the CVE page listed in the References section. Red Hat would like to thank the Curl project for reporting CVE-2017-8816, CVE-2017-8817, CVE-2017-1000254, CVE-2017-1000257, CVE-2018-1000007, CVE-2018-1000120, CVE-2018-1000122, CVE-2018-1000301, CVE-2016-9586, CVE-2017-1000100, CVE-2017-1000101, CVE-2018-14618, and CVE-2018-1000121. Upstream acknowledges Alex Nichols as the original reporter of CVE-2017-8816; the OSS-Fuzz project as the original reporter of CVE-2017-8817 and CVE-2018-1000301; Max Dymond as the original reporter of CVE-2017-1000254 and CVE-2018-1000122; Brian Carpenter and the OSS-Fuzz project as the original reporters of CVE-2017-1000257; Craig de Stigter as the original reporter of CVE-2018-1000007; Duy Phan Thanh as the original reporter of CVE-2018-1000120; Even Rouault as the original reporter of CVE-2017-1000100; Brian Carpenter as the original reporter of CVE-2017-1000101; Zhaoyang Wu as the original reporter of CVE-2018-14618; and Dario Weisser as the original reporter of CVE-2018-1000121. Bug Fix: * Previously, the Apache HTTP Server from the httpd24 Software Collection was unable to handle situations when static content was repeatedly requested in a browser by refreshing the page. As a consequence, HTTP/2 connections timed out and httpd became unresponsive. This bug has been fixed, and HTTP/2 connections now work as expected in the described scenario. Enhancement: * This update adds the mod_md module to the httpd24 Software Collection. This module enables managing domains across virtual hosts and certificate provisioning using the Automatic Certificate Management Environment protocol. The mod_md module is available only for Red Hat Enterprise Linux 7. Additional Changes: For detailed information on changes in this release, see the Red Hat Software Collections 3.2 Release Notes linked from the References section.

Platform:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Product:
httpd24-curl
httpd24-httpd
httpd24-nghttp2
Reference:
RHSA-2018:3558-01
CVE-2016-5419
CVE-2016-5420
CVE-2016-5421
CVE-2016-7141
CVE-2016-7167
CVE-2016-8615
CVE-2016-8616
CVE-2016-8617
CVE-2016-8618
CVE-2016-8619
CVE-2016-8620
CVE-2016-8621
CVE-2016-8622
CVE-2016-8623
CVE-2016-8624
CVE-2016-8625
CVE-2016-9586
CVE-2017-7407
CVE-2017-8816
CVE-2017-8817
CVE-2017-15710
CVE-2017-15715
CVE-2017-1000100
CVE-2017-1000101
CVE-2017-1000254
CVE-2017-1000257
CVE-2018-1283
CVE-2018-1301
CVE-2018-1303
CVE-2018-1312
CVE-2018-11763
CVE-2018-14618
CVE-2018-1000007
CVE-2018-1000120
CVE-2018-1000121
CVE-2018-1000122
CVE-2018-1000301
CVE    37
CVE-2017-7407
CVE-2018-14618
CVE-2017-1000257
CVE-2017-8816
...
CPE    6
cpe:/a:apache:httpd24-nghttp2
cpe:/o:redhat:enterprise_linux:7.0
cpe:/a:apache:httpd24-httpd
cpe:/o:redhat:enterprise_linux:7
...

© SecPod Technologies