INFSA-2024:4720: httpd:2.4 security update

Information about definition

Identificator: INFSA-2024:4720

Type: security

Release date: 2024-10-10 05:51:36 UTC

Information about package

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Vulnerabilities description

  • CVE-2024-38473

    A flaw was found in the mod_proxy module of httpd. Due to an encoding problem, specially crafted request URLs with incorrect encoding can be sent to backend services, potentially bypassing authentication.

  • CVE-2024-38474

    A flaw was found in the mod_rewrite module of httpd. Due to a substitution encoding issue, specially crafted requests may allow an attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant only to be executed as CGI.

  • CVE-2024-38475

    A flaw was found in the mod_rewrite module of httpd. Improper escaping of output allows an attacker to map URLs to filesystem locations permitted to be served by the server but are not intentionally or directly reachable by any URL. This issue results in code execution or source code disclosure.

  • CVE-2024-38477

    A flaw was found in the mod_proxy module of httpd. A NULL pointer dereference can be triggered when processing a specially crafted HTTP request, causing the httpd server to crash, and resulting in a denial of service.

  • CVE-2024-39573

    A flaw was found in the mod_rewrite module of httpd. A potential SSRF allows an attacker to cause unsafe rules used in the RewriteRule directive to unexpectedly set up URLs to be handled by the mod_proxy module.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 5.3 no information
no information 8.1 no information
no information 9.1 no information
no information 7.5 no information
no information 7.4 no information
Critical, important, moderate, low

Updated packages