Lucene search

K
altlinuxHttps://packages.altlinux.org/en/sisyphus/security/574CFFD250D09C9ABD89674BCC1F6357
HistoryMay 18, 2017 - 12:00 a.m.

Security fix for the ALT Linux 8 package apache2 version 1:2.4.25-alt1

2017-05-1800:00:00
https://packages.altlinux.org/en/sisyphus/security/
packages.altlinux.org
16

EPSS

0.2

Percentile

96.4%

May 18, 2017 Anton Farygin 1:2.4.25-alt1

- updated to 2.4.25 witch security fixes:
    + CVE-2016-8740 mod_http2: Mitigate DoS memory exhaustion via endless CONTINUATION frames.
    + CVE-2016-5387 core: Mitigate [f]cgi "httpoxy" issues
    + CVE-2016-2161 mod_auth_digest: Prevent segfaults during client entry allocation when the shared memory space is exhausted.
    + CVE-2016-0736 mod_session_crypto: Authenticate the session data/cookie with a MAC (SipHash) to prevent deciphering or tampering with a padding oracle attack.
- increased service startup time (closes: [#33491](<https://bugzilla.altlinux.org/33491>))
- cleanup spec and patches