Release Info

Advisory: CLSA-2024:1732194710

OS: AlmaLinux 9.2 ESU

Public date: 2024-11-21 08:11:52

Project: httpd

Version: 2.4.53-11.el9_2.5.tuxcare.els4

Errata link: https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2024-1732194710.html

Changelog

- CVE-2023-38709: faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses - CVE-2024-24795: HTTP response splitting in multiple modules allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack

Update

Update command: dnf update httpd*

Packages list

httpd-2.4.53-11.el9_2.5.tuxcare.els4.x86_64.rpm httpd-core-2.4.53-11.el9_2.5.tuxcare.els4.x86_64.rpm httpd-devel-2.4.53-11.el9_2.5.tuxcare.els4.x86_64.rpm httpd-filesystem-2.4.53-11.el9_2.5.tuxcare.els4.noarch.rpm httpd-manual-2.4.53-11.el9_2.5.tuxcare.els4.noarch.rpm httpd-tools-2.4.53-11.el9_2.5.tuxcare.els4.x86_64.rpm mod_ldap-2.4.53-11.el9_2.5.tuxcare.els4.x86_64.rpm mod_lua-2.4.53-11.el9_2.5.tuxcare.els4.x86_64.rpm mod_proxy_html-2.4.53-11.el9_2.5.tuxcare.els4.x86_64.rpm mod_session-2.4.53-11.el9_2.5.tuxcare.els4.x86_64.rpm mod_ssl-2.4.53-11.el9_2.5.tuxcare.els4.x86_64.rpm

CVEs

CVE-2023-38709
CVE-2024-24795