Lucene search

K
oraclelinuxOracleLinuxELSA-2014-1972
HistoryFeb 04, 2016 - 12:00 a.m.

httpd24-httpd security and bug fix update

2016-02-0400:00:00
linux.oracle.com
98

EPSS

0.965

Percentile

99.6%

[2.4.6-22.0.1.el6]

  • remove enable-tlsv1x-thunks to fit openssl 1.x api
  • replace index.html with Oracleโ€™s index page oracle_index.html
  • update vstring in specfile
    [2.4.6-22]
  • Remove mod_proxy_fcgi fix for heap-based buffer overflow,
    httpd-2.4.6 is not affected (CVE-2014-3583)
    [2.4.6-21]
  • mod_proxy_wstunnel: Fix the use of SSL with the โ€˜wss:โ€™ scheme (#1141950)
    [2.4.6-20]
  • core: fix bypassing of mod_headers rules via chunked requests (CVE-2013-5704)
  • mod_cache: fix NULL pointer dereference on empty Content-Type (CVE-2014-3581)
  • mod_proxy_fcgi: fix heap-based buffer overflow (CVE-2014-3583)
    [2.4.6-19]
  • mod_cgid: add security fix for CVE-2014-0231
  • mod_proxy: add security fix for CVE-2014-0117
  • mod_deflate: add security fix for CVE-2014-0118
  • mod_status: add security fix for CVE-2014-0226
  • mod_cache: add secutiry fix for CVE-2013-4352