httpd:2.4 security update
エラータID: AXSA:2022-3127:01
Release date:
Friday, March 25, 2022 - 09:27
Subject:
httpd:2.4 security update
Affected Channels:
Asianux Server 8 for x86_64
Severity:
High
Description:
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.
Security Fix(es):
* httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling (CVE-2022-22720)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2022-22720
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
Modularity name: httpd
Stream name: 2.4
Solution:
Update packages.
CVEs:
CVE-2022-22720
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
Additional Info:
N/A
Download:
SRPMS
- httpd-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.src.rpm
MD5: 714d44f9fd71ec6b38fbdf41610c5314
SHA-256: 981bc2499bade4244e2958f565ee74a0f3aafead965bd0837af63840b17e472f
Size: 6.91 MB - mod_http2-1.15.7-3.module+el8+1403+ce1f9ad8.src.rpm
MD5: 790d40c2f01583e241c150fd87731d12
SHA-256: db3d6fb308e4696359a8da3672efad68fa3a54256a55f448acf1821a52d740d6
Size: 1.01 MB - mod_md-2.0.8-8.module+el8+1403+ce1f9ad8.src.rpm
MD5: c23c9dca37e2108c8df880a2714f3a9b
SHA-256: 00372a8852c6d016cd15e3b800003d84aa9d760e22e22b24f3ff1827542ab724
Size: 635.32 kB
Asianux Server 8 for x86_64
- httpd-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
MD5: 5572fdffdf4ff5b21dd764db455f1ff9
SHA-256: 78864086b149396ec7979015932d3c0194d4af9f60a2b23bd910348a67897c69
Size: 1.41 MB - httpd-debugsource-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
MD5: 7cbcfa93c7f0b314eb53a908fb6b28af
SHA-256: 45e45f77914b4a28fde00eeb6b245480aaea54bd85147a0a094ace41ac1c93f9
Size: 1.44 MB - httpd-devel-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
MD5: 4f1bad049839f2ec97f866dd47eb1989
SHA-256: 7d4dc477bb9587672f2757f4a884a7bfd330c9100d64581c369a7cb7d9ab0553
Size: 221.77 kB - httpd-filesystem-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.noarch.rpm
MD5: 54318f6f8706eb5b850a46d007dc2334
SHA-256: 5a725ee4425bfff9a552f82600b1a150e16de6fc7c550c6f37314038d247a11e
Size: 39.12 kB - httpd-manual-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.noarch.rpm
MD5: 64097acbad397dda52ef8b1b0336cf07
SHA-256: be84020bd5daf855d0d61e6f10bc521c657cd9f4da9447f2452f15a190633f00
Size: 2.37 MB - httpd-tools-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
MD5: 5443008110d6826ce6e6adc033213c03
SHA-256: 55d79b4867d78b9b8a9833c9b1d99a7eb0b759076c834f0c7c0b6a6f0d403063
Size: 106.39 kB - mod_ldap-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
MD5: adbe59c8425229e784494c1a86d84078
SHA-256: 6318adc4a81f7232125aa69e79adcf152728d5f72b4d883bb4349c11daec20eb
Size: 84.42 kB - mod_proxy_html-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
MD5: 4dfd916707ced6acddbcfdbe3063e000
SHA-256: 8fc22ba8b04e0dcccb226f0f38ca04231abc7e8fa90bd1488cfc64e5017412ec
Size: 61.52 kB - mod_session-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
MD5: 4757706e66c40110647a008de31c79ec
SHA-256: 00c1c25bd662fb9577e94bd37f586af38d927477a55754b242e7d2b03fcadb56
Size: 73.19 kB - mod_ssl-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
MD5: 844feed35245ef1e6266c6d2b9bf3c8e
SHA-256: b37d559ef67aa69be1448a6405a682aab04f5e123d9c64926b92f0672de69fa1
Size: 135.74 kB - mod_http2-1.15.7-3.module+el8+1403+ce1f9ad8.x86_64.rpm
MD5: f85e6d14b792b7a42f58e109b70a56b8
SHA-256: b94befc2ac9179f90babf3b678a959094385c5787aeb909014da684ff0f096e0
Size: 153.15 kB - mod_http2-debugsource-1.15.7-3.module+el8+1403+ce1f9ad8.x86_64.rpm
MD5: d22744bcb01724ffc4ee84e6e5c96148
SHA-256: be9e73803bdf91c4f42178bd649e296abf76dcc499476e3ccc54a1362f1d30f1
Size: 146.91 kB - mod_md-2.0.8-8.module+el8+1403+ce1f9ad8.x86_64.rpm
MD5: 45ee9e2c693e8dd4e2898f9beb6b7ea0
SHA-256: fd34c133b05040cd02fe6aca69daa87da8e023e9ad512f768bdfacae2754713f
Size: 183.57 kB - mod_md-debugsource-2.0.8-8.module+el8+1403+ce1f9ad8.x86_64.rpm
MD5: bd30d9e449d17bcba03f351410ee06cf
SHA-256: 161863535b93da882f35ffd3e9128b8e29d97a1c591b3580b8be773c91f01e1c
Size: 126.24 kB