rpm package
almalinux/mod_http2
pkg:rpm/almalinux/mod_http2
Vulnerabilities (66)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-26691 | Cri | 9.8 | < 1.15.7-3.module_el8.5.0+2609+b30d9eec | 1.15.7-3.module_el8.5.0+2609+b30d9eec | Jun 10, 2021 | In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow | |
| CVE-2021-26690 | Hig | 7.5 | < 1.15.7-3.module_el8.5.0+2609+b30d9eec | 1.15.7-3.module_el8.5.0+2609+b30d9eec | Jun 10, 2021 | Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service | |
| CVE-2020-35452 | Hig | 7.3 | < 1.15.7-5.module_el8.6.0+2872+fe0ff7aa | 1.15.7-5.module_el8.6.0+2872+fe0ff7aa | Jun 10, 2021 | Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation | |
| CVE-2020-11993 | Hig | 7.5 | < 1.15.7-3.module_el8.5.0+2609+b30d9eec | 1.15.7-3.module_el8.5.0+2609+b30d9eec | Aug 7, 2020 | Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" w | |
| CVE-2020-11984 | Cri | 9.8 | < 1.15.7-3.module_el8.5.0+2609+b30d9eec | 1.15.7-3.module_el8.5.0+2609+b30d9eec | Aug 7, 2020 | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE | |
| CVE-2018-17199 | Hig | 7.5 | < 1.15.7-3.module_el8.5.0+2609+b30d9eec | 1.15.7-3.module_el8.5.0+2609+b30d9eec | Jan 30, 2019 | In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded. |
- affected < 1.15.7-3.module_el8.5.0+2609+b30d9eecfixed 1.15.7-3.module_el8.5.0+2609+b30d9eec
In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow
- affected < 1.15.7-3.module_el8.5.0+2609+b30d9eecfixed 1.15.7-3.module_el8.5.0+2609+b30d9eec
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service
- affected < 1.15.7-5.module_el8.6.0+2872+fe0ff7aafixed 1.15.7-5.module_el8.6.0+2872+fe0ff7aa
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation
- affected < 1.15.7-3.module_el8.5.0+2609+b30d9eecfixed 1.15.7-3.module_el8.5.0+2609+b30d9eec
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" w
- affected < 1.15.7-3.module_el8.5.0+2609+b30d9eecfixed 1.15.7-3.module_el8.5.0+2609+b30d9eec
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
- affected < 1.15.7-3.module_el8.5.0+2609+b30d9eecfixed 1.15.7-3.module_el8.5.0+2609+b30d9eec
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.
Page 4 of 4