httpd:2.4 bug fix and enhancement update
エラータID: AXBA:2025-11626:01
リリース日:
2025/12/26 Friday - 11:01
題名:
httpd:2.4 bug fix and enhancement update
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
N/A
解決策:
Update packages.
CVE:
CVE-2025-23048
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client certificates (for example with a different SSLCACertificateFile/Path setting). In such a case, a client trusted to access one virtual host may be able to access another virtual host, if SSLStrictSNIVHostCheck is not enabled in either virtual host.
追加情報:
N/A
ダウンロード:
SRPMS
- httpd-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.src.rpm
MD5: b580332ee2d14f62bd1e974e045add18
SHA-256: b51be2180c0760a4e179460db84859bc5f6d108d8057c005580b111a309c8cb3
Size: 6.99 MB - mod_http2-1.15.7-10.module+el8+1929+7de19bfb.4.src.rpm
MD5: 8d384dc1ed7283cb46d2edbffd67878d
SHA-256: a7d741245f017076f567710f1a18259cc5a389b081eda9e75f6ccff910fceeec
Size: 1.02 MB - mod_md-2.0.8-8.module+el8+1929+7de19bfb.src.rpm
MD5: 37066c6d76b12ad0104723263e0f0ed7
SHA-256: 53328b70aee320211ce28e0c35b5bc09abd216d2ee0551fb16eccda961f829b3
Size: 635.32 kB
Asianux Server 8 for x86_64
- httpd-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.x86_64.rpm
MD5: 44430e3beceee0ee75a6ba7f05e58af2
SHA-256: 01e0e84b8bc9933db3ad03f8a93c8d5a07a85fa0441665678c94b511af2046bd
Size: 1.42 MB - httpd-debugsource-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.x86_64.rpm
MD5: 35f4431ec20d4fea39d2e92817635825
SHA-256: 43e25381b99b74b6655f76e2221c286376db1e57e1e42535cc55f9a6c0db5827
Size: 1.46 MB - httpd-devel-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.x86_64.rpm
MD5: 9a8eee74b78453a9d6b29ddb5aebe540
SHA-256: ea8a6993a4efcb7bc705d07c914cf5925daee9c202ff163d3a3267ea78c9f2e1
Size: 229.02 kB - httpd-filesystem-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.noarch.rpm
MD5: 88c3a6a835fe2705c975d4a8b3534ac2
SHA-256: e2df8b68f076d2d52fddcba62a1acc771eb227538d28ae30bddf73d1a18f862c
Size: 45.16 kB - httpd-manual-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.noarch.rpm
MD5: 12d0da27393fbdcfde3670fae01c9023
SHA-256: ceae94768cd424507a6e29ecf688802613453e21199cec87883add98b7db61ac
Size: 2.38 MB - httpd-tools-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.x86_64.rpm
MD5: 5f5c6277c39d3186b34ef2f5e1c75ff7
SHA-256: 1fb8b9ebbe225b5e6818e3719e6c043067108195c2789aa5d0a2bee42c4c6be6
Size: 112.28 kB - mod_http2-1.15.7-10.module+el8+1929+7de19bfb.4.x86_64.rpm
MD5: 3b8b38408d16f8d3b4e6520ed6896e5a
SHA-256: e98006fb80efa45f6406fc4872b151981cd179306d978a80441f2feb6d47a580
Size: 155.01 kB - mod_http2-debugsource-1.15.7-10.module+el8+1929+7de19bfb.4.x86_64.rpm
MD5: d94736fb26f1a39ce28163a286fe5fa4
SHA-256: ebfe320bf3175ff2a3b213f2dfa94a3fc23601b27793d18fcec054b200b6f88f
Size: 148.67 kB - mod_ldap-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.x86_64.rpm
MD5: 209210c6ec616f4d932a907a3a2f6c74
SHA-256: d5d19dd9f2f81cc3d96191ff033c2787a01ed1820883a2b14bfaedbf6e45f0b1
Size: 90.47 kB - mod_md-2.0.8-8.module+el8+1929+7de19bfb.x86_64.rpm
MD5: cdd6a794633f3428bcde62a6da1422a2
SHA-256: 130cace68e2015f7a2f5249ab8d1f497c759ef00a735b21478e03de6fd38953f
Size: 183.66 kB - mod_md-debugsource-2.0.8-8.module+el8+1929+7de19bfb.x86_64.rpm
MD5: bc3d85ca4f04a2adf74aefcee2aaa9db
SHA-256: ecdfb5e06b55b6fb02f14db9ccfc2d568f39c4082f13e052d9c658a3d6010483
Size: 126.24 kB - mod_proxy_html-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.x86_64.rpm
MD5: 54df9657b59f2e415c81a3e98f369e7c
SHA-256: bdb59da4fe6cafd80d2a7c5ac66bf98e234cd5a9e05335545c5ccef69e6384cb
Size: 67.66 kB - mod_session-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.x86_64.rpm
MD5: 240eb43d90fd244acfd74ea6d69e529a
SHA-256: 3458c277b9f1ce60315caa74f9bfd5f2c170c1438d635058ad1518c494cceafc
Size: 79.24 kB - mod_ssl-2.4.37-65.module+el8+1929+7de19bfb.6.ML.1.x86_64.rpm
MD5: aa163463037d00c51c539dea4e268a88
SHA-256: 00b6ab36d7418308d70c3113600f181ea859d866f3651ad516f23230240e422b
Size: 142.62 kB