httpd:2.4 security update

エラータID: AXSA:2022-3127:01

Release date: 
Friday, March 25, 2022 - 09:27
Subject: 
httpd:2.4 security update
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

* httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling (CVE-2022-22720)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2022-22720
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

Modularity name: httpd
Stream name: 2.4

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. httpd-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.src.rpm
    MD5: 714d44f9fd71ec6b38fbdf41610c5314
    SHA-256: 981bc2499bade4244e2958f565ee74a0f3aafead965bd0837af63840b17e472f
    Size: 6.91 MB
  2. mod_http2-1.15.7-3.module+el8+1403+ce1f9ad8.src.rpm
    MD5: 790d40c2f01583e241c150fd87731d12
    SHA-256: db3d6fb308e4696359a8da3672efad68fa3a54256a55f448acf1821a52d740d6
    Size: 1.01 MB
  3. mod_md-2.0.8-8.module+el8+1403+ce1f9ad8.src.rpm
    MD5: c23c9dca37e2108c8df880a2714f3a9b
    SHA-256: 00372a8852c6d016cd15e3b800003d84aa9d760e22e22b24f3ff1827542ab724
    Size: 635.32 kB

Asianux Server 8 for x86_64
  1. httpd-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
    MD5: 5572fdffdf4ff5b21dd764db455f1ff9
    SHA-256: 78864086b149396ec7979015932d3c0194d4af9f60a2b23bd910348a67897c69
    Size: 1.41 MB
  2. httpd-debugsource-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
    MD5: 7cbcfa93c7f0b314eb53a908fb6b28af
    SHA-256: 45e45f77914b4a28fde00eeb6b245480aaea54bd85147a0a094ace41ac1c93f9
    Size: 1.44 MB
  3. httpd-devel-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
    MD5: 4f1bad049839f2ec97f866dd47eb1989
    SHA-256: 7d4dc477bb9587672f2757f4a884a7bfd330c9100d64581c369a7cb7d9ab0553
    Size: 221.77 kB
  4. httpd-filesystem-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.noarch.rpm
    MD5: 54318f6f8706eb5b850a46d007dc2334
    SHA-256: 5a725ee4425bfff9a552f82600b1a150e16de6fc7c550c6f37314038d247a11e
    Size: 39.12 kB
  5. httpd-manual-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.noarch.rpm
    MD5: 64097acbad397dda52ef8b1b0336cf07
    SHA-256: be84020bd5daf855d0d61e6f10bc521c657cd9f4da9447f2452f15a190633f00
    Size: 2.37 MB
  6. httpd-tools-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
    MD5: 5443008110d6826ce6e6adc033213c03
    SHA-256: 55d79b4867d78b9b8a9833c9b1d99a7eb0b759076c834f0c7c0b6a6f0d403063
    Size: 106.39 kB
  7. mod_ldap-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
    MD5: adbe59c8425229e784494c1a86d84078
    SHA-256: 6318adc4a81f7232125aa69e79adcf152728d5f72b4d883bb4349c11daec20eb
    Size: 84.42 kB
  8. mod_proxy_html-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
    MD5: 4dfd916707ced6acddbcfdbe3063e000
    SHA-256: 8fc22ba8b04e0dcccb226f0f38ca04231abc7e8fa90bd1488cfc64e5017412ec
    Size: 61.52 kB
  9. mod_session-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
    MD5: 4757706e66c40110647a008de31c79ec
    SHA-256: 00c1c25bd662fb9577e94bd37f586af38d927477a55754b242e7d2b03fcadb56
    Size: 73.19 kB
  10. mod_ssl-2.4.37-43.module+el8+1403+ce1f9ad8.3.ML.1.x86_64.rpm
    MD5: 844feed35245ef1e6266c6d2b9bf3c8e
    SHA-256: b37d559ef67aa69be1448a6405a682aab04f5e123d9c64926b92f0672de69fa1
    Size: 135.74 kB
  11. mod_http2-1.15.7-3.module+el8+1403+ce1f9ad8.x86_64.rpm
    MD5: f85e6d14b792b7a42f58e109b70a56b8
    SHA-256: b94befc2ac9179f90babf3b678a959094385c5787aeb909014da684ff0f096e0
    Size: 153.15 kB
  12. mod_http2-debugsource-1.15.7-3.module+el8+1403+ce1f9ad8.x86_64.rpm
    MD5: d22744bcb01724ffc4ee84e6e5c96148
    SHA-256: be9e73803bdf91c4f42178bd649e296abf76dcc499476e3ccc54a1362f1d30f1
    Size: 146.91 kB
  13. mod_md-2.0.8-8.module+el8+1403+ce1f9ad8.x86_64.rpm
    MD5: 45ee9e2c693e8dd4e2898f9beb6b7ea0
    SHA-256: fd34c133b05040cd02fe6aca69daa87da8e023e9ad512f768bdfacae2754713f
    Size: 183.57 kB
  14. mod_md-debugsource-2.0.8-8.module+el8+1403+ce1f9ad8.x86_64.rpm
    MD5: bd30d9e449d17bcba03f351410ee06cf
    SHA-256: 161863535b93da882f35ffd3e9128b8e29d97a1c591b3580b8be773c91f01e1c
    Size: 126.24 kB