httpd:2.4 security update
エラータID: AXSA:2023-6424:01
リリース日:
2023/09/22 Friday - 01:24
題名:
httpd:2.4 security update
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- Apache HTTP Server の mod_proxy_uwsgi モジュールには、リモートの
攻撃者により、HTTP レスポンススマグリング攻撃を可能とする脆弱性が
存在します。(CVE-2023-27522)
Modularity name: httpd
Stream name: 2.4
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2023-27522
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
追加情報:
N/A
ダウンロード:
SRPMS
- httpd-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.src.rpm
MD5: aaaf0b963a84b462bccacd144c6928e7
SHA-256: d1d93b7d4284fc33bc689ee017ab5497c787d042d2c16094d6f71c9978a99e7d
Size: 6.95 MB - mod_http2-1.15.7-8.module+el8+1658+4f17891e.3.src.rpm
MD5: d02619e4b561511c6c64e770e9eba3e8
SHA-256: b14bb940c934e4b677e1f24b180fb29286ba67417f55e00319c57515b00275a8
Size: 1.01 MB - mod_md-2.0.8-8.module+el8+1658+4f17891e.src.rpm
MD5: 39534a7c58801e8a10550efc827434cc
SHA-256: fe65a48f63eaceca8b2c1545b9d4cb83fcb0b3d1444cb8c3a0559531ac987bf0
Size: 635.32 kB
Asianux Server 8 for x86_64
- httpd-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.x86_64.rpm
MD5: a5fa91362437372f846e0f51d6cba2b6
SHA-256: 30cbf33c05ac06dc7839578232cd86d04344bacb212775e2a5b06e5f8af121d9
Size: 1.41 MB - httpd-debugsource-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.x86_64.rpm
MD5: 7cf079e4f6471680938f526e578e981c
SHA-256: 8a592d34c8db696669b289e5e0ee0f577e8302a5721a520e1ad78edfcbe941a7
Size: 1.45 MB - httpd-devel-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.x86_64.rpm
MD5: 456a9a9d2d0e93513028b5463c732b9c
SHA-256: 2fc35bdcdece7819e36c693f8de707bf8344e559e35dc403116bc4fd61a381a5
Size: 225.51 kB - httpd-filesystem-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.noarch.rpm
MD5: 8a8105ab7fed7307bfabad8223ec6e06
SHA-256: 36a35271d6ed9f0a6e1a42522c875c6188fb20393f057ddb44a08795bf2f2b2b
Size: 42.34 kB - httpd-manual-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.noarch.rpm
MD5: d026502421fb3302c88fd54c3cabaada
SHA-256: 4018e4765f7411820d5a9600002206d83e40be798dfd338b127a331ade8bace4
Size: 2.38 MB - httpd-tools-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.x86_64.rpm
MD5: 43d6b55e4facc00d82ac4cd4abf43821
SHA-256: 421461ea7f90072834caf048fa4c468de39daa7a4775ab7dda8c3509cc7f5a99
Size: 109.40 kB - mod_http2-1.15.7-8.module+el8+1658+4f17891e.3.x86_64.rpm
MD5: 22dec9c41ee295ff599d0fd009c06116
SHA-256: 21b36c3b9b39c3cda6b96c3e26fff7bc43d0d44ce5000f32a6ed6e86ddd8b91b
Size: 153.73 kB - mod_http2-debugsource-1.15.7-8.module+el8+1658+4f17891e.3.x86_64.rpm
MD5: 401561a8fbcc9ae427f6a9aa0cbc763e
SHA-256: fba0533c0864498032f2399e38dd714cadf757f5931ec0bcae277cd62ee202db
Size: 147.25 kB - mod_ldap-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.x86_64.rpm
MD5: e2f2659ad1c739e978e2d3655873a4b8
SHA-256: ebfdb7a20d4e1d91b8308cfb6af7b72f2a94d89c3994d1c199a6441b51d77e57
Size: 87.67 kB - mod_md-2.0.8-8.module+el8+1658+4f17891e.x86_64.rpm
MD5: e4c066fc4882678c5411bac49ff144be
SHA-256: afd0cd74aae597c2842e6a3966340d4f2982840f1abb82ccf351241eecca0096
Size: 183.66 kB - mod_md-debugsource-2.0.8-8.module+el8+1658+4f17891e.x86_64.rpm
MD5: 3a14100389c6c8f9d37d12a188d9acf0
SHA-256: 8680caff24b4dec758df482e21a70e779a1e8f214861804ebb8b3152ac26527a
Size: 126.24 kB - mod_proxy_html-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.x86_64.rpm
MD5: 323855d9f3d7f2c475a02a38d2eda21e
SHA-256: 0843fbb05e5bfecd4cb7dca659250adc8b078952d9abc035414af3e14028acd9
Size: 64.76 kB - mod_session-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.x86_64.rpm
MD5: 9af06f9bf453baeb0a77ca6dc85a2219
SHA-256: 98b0cc853b2f5d42f5d8599700c6ccc70599dc9bfc9c8781ae889f2a98e1f585
Size: 76.46 kB - mod_ssl-2.4.37-56.module+el8+1658+4f17891e.7.ML.1.x86_64.rpm
MD5: a65f8d7ba4add07471affe21232b9229
SHA-256: 2e1c974bd548c7fe425c37f57bb1d9faa1d944fcb25cc6dc291562db47e61837
Size: 139.05 kB