INFSA-2025:15095: httpd security update
Information about definition
Identificator: INFSA-2025:15095
Type: security
Release date: 2025-09-11 13:59:20 UTC
Information about package
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.
Vulnerabilities description
- CVE-2024-47252
A vulnerability was found in the Apache HTTP Server. Insufficient escaping of user-supplied data in mod_ssl allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by mod_ssl such as SSL_TLS_SNI, no escaping is performed by either mod_log_config or mod_ssl and unsanitized data provided by the client may appear in log files.
- CVE-2025-23048
An access control bypass vulnerability was found in Apache httpd. The Apache HTTP Server with some mod_ssl configurations can bypass the access controls by trusted clients using TLS 1.3 session resumption. A client trusted to access one virtual host may be able to access another if SSLStrictSNIVHostCheck is not enabled on either host.
- CVE-2025-49812
An HTTP session hijacking flaw was found in Apache httpd. In some mod_ssl configurations on Apache HTTP Server, an HTTP desynchronization attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2024-47252
|
no information | 7.5 | no information |
NIST — CVE-2025-23048
|
no information | 7.5 | no information |
NIST — CVE-2025-49812
|
no information | 7.5 | no information |
Updated packages