rpm package
almalinux/httpd-tools
pkg:rpm/almalinux/httpd-tools
Vulnerabilities (66)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-39275 | Cri | 9.8 | < 2.4.37-43.module_el8.5.0+2630+51c6d843.2.alma | 2.4.37-43.module_el8.5.0+2630+51c6d843.2.alma | Sep 16, 2021 | ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| CVE-2021-36160 | Hig | 7.5 | < 2.4.37-47.module_el8.6.0+2935+fb177b09.2 | 2.4.37-47.module_el8.6.0+2935+fb177b09.2 | Sep 16, 2021 | A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive). | |
| CVE-2021-34798 | Hig | 7.5 | < 2.4.37-43.module_el8.5.0+2630+51c6d843.2.alma | 2.4.37-43.module_el8.5.0+2630+51c6d843.2.alma | Sep 16, 2021 | Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| CVE-2021-33193 | Hig | 7.5 | < 2.4.37-47.module_el8.6.0+2935+fb177b09.2 | 2.4.37-47.module_el8.6.0+2935+fb177b09.2 | Aug 16, 2021 | A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48. | |
| CVE-2021-26691 | Cri | 9.8 | < 2.4.37-43.module_el8.5.0+2597+c4b14997.alma | 2.4.37-43.module_el8.5.0+2597+c4b14997.alma | Jun 10, 2021 | In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow | |
| CVE-2020-35452 | Hig | 7.3 | < 2.4.37-47.module_el8.6.0+2935+fb177b09.2 | 2.4.37-47.module_el8.6.0+2935+fb177b09.2 | Jun 10, 2021 | Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation |
- affected < 2.4.37-43.module_el8.5.0+2630+51c6d843.2.almafixed 2.4.37-43.module_el8.5.0+2630+51c6d843.2.alma
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
- affected < 2.4.37-47.module_el8.6.0+2935+fb177b09.2fixed 2.4.37-47.module_el8.6.0+2935+fb177b09.2
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
- affected < 2.4.37-43.module_el8.5.0+2630+51c6d843.2.almafixed 2.4.37-43.module_el8.5.0+2630+51c6d843.2.alma
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
- affected < 2.4.37-47.module_el8.6.0+2935+fb177b09.2fixed 2.4.37-47.module_el8.6.0+2935+fb177b09.2
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
- affected < 2.4.37-43.module_el8.5.0+2597+c4b14997.almafixed 2.4.37-43.module_el8.5.0+2597+c4b14997.alma
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
- affected < 2.4.37-47.module_el8.6.0+2935+fb177b09.2fixed 2.4.37-47.module_el8.6.0+2935+fb177b09.2
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation
Page 4 of 4