Re: [BLFS Trac] #23251: httpd-2.4.67
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23251: httpd-2.4.67
-------------------------+------------------------
Reporter: Bruce Dubbs | Owner: blfs-book
Type: enhancement | Status: new
Priority: high | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Resolution:
Keywords: |
-------------------------+------------------------
Changes (by Joe Locash):
* priority: normal => high
Comment:
CVE's fixed in this release:
- important: Apache HTTP Server: http2: double free and possible RCE on
early reset (CVE-2026-23918)
- moderate: Apache HTTP Server: mod_rewrite elevation of privileges via
ap_expr (CVE-2026-24072)
- low: Apache HTTP Server: buffer overflow in mod_proxy_ajp via
ajp_msg_check_header() (CVE-2026-28780)
- low: Apache HTTP Server: mod_md unrestricted OCSP response
(CVE-2026-29168)
- low: Apache HTTP Server: mod_dav_lock indirect lock crash
(CVE-2026-29169)
- moderate: Apache HTTP Server: mod_auth_digest timing attack
(CVE-2026-33006)
- low: Apache HTTP Server: mod_authn_socache crash (CVE-2026-33007)
- low: Apache HTTP Server: multiple modules: HTTP response splitting
forwarding malicious status line (CVE-2026-33523)
- low: Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
(CVE-2026-33857)
- low: Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to
Missing Null-Termination Check (ajp_msg_get_string) (CVE-2026-34032)
- low: Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)
https://httpd.apache.org/security/vulnerabilities_24.html
{{{
Changes with Apache 2.4.67
*) mod_md: update to version 2.6.10
- Fix issue #420 <https://github.com/icing/mod_md/issues/420> by
ignoring
job.json files that claim to have completely finished a certificate
renewal, but have not produced the necessary result files.
*) mod_http2: update to version 2.0.39
Remove streams own memory allocator after reports of memory problems
with third party modules.
[Stefan Eissing]
*) mod_http2: update to version 2.0.38
Source sync with mod_h2 github repository. No functional change.
[Stefan Eissing]
*) Updated conf/mime.types: added vnd.sqlite3, HEIC, HEIF
[Alexandru Mărășteanu <hello alexei.ro>]
*) mod_md: update to version 2.6.7
- Fix a regression in `MDStapleOthers` which broke in v2.6.0 and no
longer
applied, no matter the configuration.
*) mod_md: update to version 2.6.9
- Pebble 2.9+ reports another error when terms of service agreement
is
not set. Treating all "userActionRequired" errors as permanent now.
*) mod_md: update to version 2.6.8
- Fix the ARI related `replaces` property in ACME order creation to
only
be used when the CA supports ARI and it is enabled in the menu
config.
- Fix compatibility with APR versions before 1.6.0 which do not have
`apr_cstr_casecmp` and should use `apr_strnatcasecmp` instead.
*) mod_http2: update to version 2.0.37
Prevent double purge of a stream, resulting in a double free.
Fixes PR 69899.
[Stefan Eissing]
*) mod_md: Use correct function name when compiling against APR < 1.6.0.
PR 69954 [Tần Quảng <[email protected]>]
}}}
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23251#comment:1>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page