Release Info

Advisory: CLSA-2023:1695752598

OS: CentOS 7 ELS

Public date: 2023-09-26 14:23:20

Project: httpd

Version: 2.4.6-99.el7.centos.1.tuxcare.els1

Errata link: https://errata.tuxcare.com/els_os/centos7els/CLSA-2023-1695752598.html

Changelog

- CVE-2022-23943: Fix out-of-bound write in mod_sed - CVE-2022-22721: Fix integer overflow which resulted in out-of-bounds write - CVE-2022-28615: Fix read beyond bounds in ap_strcmp_match() - CVE-2022-31813: Fix possible bypass of IP based authentication

Update

Update command: yum update httpd*

Packages list

httpd-2.4.6-99.el7.centos.1.tuxcare.els1.x86_64.rpm httpd-devel-2.4.6-99.el7.centos.1.tuxcare.els1.x86_64.rpm httpd-manual-2.4.6-99.el7.centos.1.tuxcare.els1.noarch.rpm httpd-tools-2.4.6-99.el7.centos.1.tuxcare.els1.x86_64.rpm mod_ldap-2.4.6-99.el7.centos.1.tuxcare.els1.x86_64.rpm mod_proxy_html-2.4.6-99.el7.centos.1.tuxcare.els1.x86_64.rpm mod_session-2.4.6-99.el7.centos.1.tuxcare.els1.x86_64.rpm mod_ssl-2.4.6-99.el7.centos.1.tuxcare.els1.x86_64.rpm

CVEs

CVE-2022-23943
CVE-2022-31813
CVE-2022-28615
CVE-2022-22721