Lucene search

K
freebsdFreeBSD5D921A8C-3A43-11EF-B611-84A93843EB75
HistoryJul 04, 2024 - 12:00 a.m.

Apache httpd -- source code disclosure

2024-07-0400:00:00
vuxml.freebsd.org
15
apache httpd
source code
disclosure
addtype
security issue
unix

AI Score

6.9

Confidence

Low

EPSS

0

Percentile

16.0%

The Apache httpd project reports:

isource code disclosure with handlers configured via AddType
(CVE-2024-39884) (Important). A regression in the core of Apache HTTP
Server 2.4.60 ignores some use of the legacy content-type based
configuration of handlers. “AddType” and similar configuration,
under some circumstances where files are requested indirectly, result
in source code disclosure of local content. For example, PHP scripts
may be served instead of interpreted.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchapache24= 2.4.60UNKNOWN
FreeBSDanynoarchapache24< 2.4.61UNKNOWN