Re: [BLFS Trac] #23251: httpd-2.4.67

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23251: httpd-2.4.67
-------------------------+------------------------
 Reporter:  Bruce Dubbs  |       Owner:  blfs-book
     Type:  enhancement  |      Status:  new
 Priority:  high         |   Milestone:  13.1
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+------------------------
Changes (by Joe Locash):

 * priority:  normal => high

Comment:

 CVE's fixed in this release:
  - important: Apache HTTP Server: http2: double free and possible RCE on
 early reset (CVE-2026-23918)
  - moderate: Apache HTTP Server: mod_rewrite elevation of privileges via
 ap_expr (CVE-2026-24072)
  - low: Apache HTTP Server: buffer overflow in mod_proxy_ajp via
 ajp_msg_check_header() (CVE-2026-28780)
  - low: Apache HTTP Server: mod_md unrestricted OCSP response
 (CVE-2026-29168)
  - low: Apache HTTP Server: mod_dav_lock indirect lock crash
 (CVE-2026-29169)
  - moderate: Apache HTTP Server: mod_auth_digest timing attack
 (CVE-2026-33006)
  - low: Apache HTTP Server: mod_authn_socache crash (CVE-2026-33007)
  - low: Apache HTTP Server: multiple modules: HTTP response splitting
 forwarding malicious status line (CVE-2026-33523)
  - low: Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
 (CVE-2026-33857)
  - low: Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to
 Missing Null-Termination Check (ajp_msg_get_string) (CVE-2026-34032)
  - low: Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory
 disclosure in ajp_parse_data() (CVE-2026-34059)

 https://httpd.apache.org/security/vulnerabilities_24.html

 {{{
 Changes with Apache 2.4.67

   *) mod_md: update to version 2.6.10
      - Fix issue #420 <https://github.com/icing/mod_md/issues/420> by
 ignoring
        job.json files that claim to have completely finished a certificate
        renewal, but have not produced the necessary result files.

   *) mod_http2: update to version 2.0.39
      Remove streams own memory allocator after reports of memory problems
      with third party modules.
      [Stefan Eissing]

   *) mod_http2: update to version 2.0.38
      Source sync with mod_h2 github repository. No functional change.
      [Stefan Eissing]

   *) Updated conf/mime.types: added vnd.sqlite3, HEIC, HEIF
      [Alexandru Mărășteanu <hello alexei.ro>]

   *) mod_md: update to version 2.6.7
      - Fix a regression in `MDStapleOthers` which broke in v2.6.0 and no
 longer
        applied, no matter the configuration.

   *) mod_md: update to version 2.6.9
      - Pebble 2.9+ reports another error when terms of service agreement
 is
        not set. Treating all "userActionRequired" errors as permanent now.

   *) mod_md: update to version 2.6.8
      - Fix the ARI related `replaces` property in ACME order creation to
 only
        be used when the CA supports ARI and it is enabled in the menu
 config.
      - Fix compatibility with APR versions before 1.6.0 which do not have
        `apr_cstr_casecmp` and should use `apr_strnatcasecmp` instead.

   *) mod_http2: update to version 2.0.37
      Prevent double purge of a stream, resulting in a double free.
      Fixes PR 69899.
      [Stefan Eissing]

   *) mod_md: Use correct function name when compiling against APR < 1.6.0.
      PR 69954 [Tần Quảng <[email protected]>]
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23251#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.