httpd-2.2.15-60.5.0.1.AXS4

エラータID: AXSA:2017-1918:04

リリース日: 
2017/08/29 Tuesday - 14:55
題名: 
httpd-2.2.15-60.5.0.1.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

The Apache HTTP Server is a powerful, efficient, and extensible
web server.

CVE-2017-3167
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of
the ap_get_basic_auth_pw() by third-party modules outside of the
authentication phase may lead to authentication requirements being
bypassed.
CVE-2017-3169
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl
may dereference a NULL pointer when third-party modules call
ap_hook_process_connection() during an HTTP request to an HTTPS port.
CVE-2017-7679
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime
can read one byte past the end of a buffer when sending a malicious
Content-Type response header.
CVE-2017-9788
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value
placeholder in [Proxy-]Authorization headers of type 'Digest' was not
initialized or reset before or between successive key=value
assignments by mod_auth_digest. Providing an initial key with no '='
assignment could reflect the stale value of uninitialized pool memory
used by the prior request, leading to leakage of potentially
confidential information, and a segfault in other cases resulting in
denial of service.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. httpd-2.2.15-60.5.0.1.AXS4.src.rpm
    MD5: baadae3d9825eb1163e03a117bad3519
    SHA-256: 311a4ef1ce82480b76648b0690d06b99adab211b433eb4ba37836cfc435d1478
    Size: 6.49 MB

Asianux Server 4 for x86
  1. httpd-2.2.15-60.5.0.1.AXS4.i686.rpm
    MD5: 3413584f79eaebaf4d87c5ff855680a0
    SHA-256: ea08c06d6150259a36a497a18f7066df02f414cd3ac62527c012e661b4206c8c
    Size: 843.30 kB
  2. httpd-devel-2.2.15-60.5.0.1.AXS4.i686.rpm
    MD5: 123d771e4c80ac230941e2a05106985f
    SHA-256: 6486777dd729bd252b3c9d786547bbd2e935c0f9130632e8ce002e214b8dccab
    Size: 157.98 kB
  3. httpd-manual-2.2.15-60.5.0.1.AXS4.noarch.rpm
    MD5: 1f159b57604ca2ff21011f474255aea7
    SHA-256: ba5b281aa6aa79f1f9c7748bab3e80241de609023775693918d9be2ced931f4d
    Size: 791.71 kB
  4. httpd-tools-2.2.15-60.5.0.1.AXS4.i686.rpm
    MD5: 544dfaf634cb9c0865211dce739a5278
    SHA-256: 754b3ba0755479d91bbdfbc62192ca5efac8b85dc3886fc2c50829adddacec45
    Size: 80.40 kB
  5. mod_ssl-2.2.15-60.5.0.1.AXS4.i686.rpm
    MD5: d8d7e83ac7f40f6a191684a8152304d2
    SHA-256: 21d8766e6f926fce6c6bc0c74245ef4b617dafa69f3601acc39fc024c2d29726
    Size: 98.96 kB

Asianux Server 4 for x86_64
  1. httpd-2.2.15-60.5.0.1.AXS4.x86_64.rpm
    MD5: 0ea0153109b6bb3e186d269819a2ae21
    SHA-256: 278ddeeb9a5ce9bdabf31475a066186a7560deb4a11464c6fd84289e4d5594dd
    Size: 837.69 kB
  2. httpd-devel-2.2.15-60.5.0.1.AXS4.x86_64.rpm
    MD5: d3adf60699b71f1bc4287ef27f4769a7
    SHA-256: e8674d5bb72dad2dcb5e33f9611e4d64d72c92b25972be81886895667169f63a
    Size: 157.53 kB
  3. httpd-manual-2.2.15-60.5.0.1.AXS4.noarch.rpm
    MD5: 8c24f916a311f3258734523237ea20c5
    SHA-256: eed3e72f06d99fb9ba60c716d6245d6e58b3ad0d455247a9ff1569621893d3a3
    Size: 791.31 kB
  4. httpd-tools-2.2.15-60.5.0.1.AXS4.x86_64.rpm
    MD5: 3a4f9cb5a9c576b4ab956713c379c82e
    SHA-256: 8f9b03c3ab3751dce0f7a60db2f9dc7b1cc138f7dd0affdb8fd1207d20db6fd7
    Size: 79.39 kB
  5. mod_ssl-2.2.15-60.5.0.1.AXS4.x86_64.rpm
    MD5: 675f2b5a8afd025c92c307b12bf6d0e4
    SHA-256: 23710733c592ff37e84fc9464062ba2ae0c693462b607c9d7ca9f59f1dd27084
    Size: 97.58 kB
  6. httpd-devel-2.2.15-60.5.0.1.AXS4.i686.rpm
    MD5: 123d771e4c80ac230941e2a05106985f
    SHA-256: 6486777dd729bd252b3c9d786547bbd2e935c0f9130632e8ce002e214b8dccab
    Size: 157.98 kB