INFSA-2024:4720: httpd:2.4 security update
Information about definition
Identificator: INFSA-2024:4720
Type: security
Release date: 2024-10-10 05:51:36 UTC
Information about package
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.
Vulnerabilities description
- CVE-2024-38473
A flaw was found in the mod_proxy module of httpd. Due to an encoding problem, specially crafted request URLs with incorrect encoding can be sent to backend services, potentially bypassing authentication.
- CVE-2024-38474
A flaw was found in the mod_rewrite module of httpd. Due to a substitution encoding issue, specially crafted requests may allow an attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant only to be executed as CGI.
- CVE-2024-38475
A flaw was found in the mod_rewrite module of httpd. Improper escaping of output allows an attacker to map URLs to filesystem locations permitted to be served by the server but are not intentionally or directly reachable by any URL. This issue results in code execution or source code disclosure.
- CVE-2024-38477
A flaw was found in the mod_proxy module of httpd. A NULL pointer dereference can be triggered when processing a specially crafted HTTP request, causing the httpd server to crash, and resulting in a denial of service.
- CVE-2024-39573
A flaw was found in the mod_rewrite module of httpd. A potential SSRF allows an attacker to cause unsafe rules used in the RewriteRule directive to unexpectedly set up URLs to be handled by the mod_proxy module.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2024-38473
|
no information | 5.3 | no information |
NIST — CVE-2024-38474
|
no information | 8.1 | no information |
NIST — CVE-2024-38475
|
no information | 9.1 | no information |
NIST — CVE-2024-38477
|
no information | 7.5 | no information |
NIST — CVE-2024-39573
|
no information | 7.4 | no information |
Updated packages