Lucene search
Basic search
Lucene search
Search by product
Subscribe
K
Start 30-day trial
Database
Vendors
Products
Years
CVSS
Scanner
Agent Scanning
API Scanning
Manual Audit
Perimeter Scanner
Scanning
Projects
Email
Webhook
Plugins
Resources
Documents
Blog
Glossary
FAQ
Pricing
Contacts
About Us
Partners
Branding Guideline
SIGN IN
OracleLinux
ELSA-2023-0852
History
Feb 22, 2023 - 12:00 a.m.
Vulners
/
Oraclelinux
/
httpd:2.4 security and bug fix update
httpd:2.4 security and bug fix update
2023-02-22
00:00:00
linux.oracle.com
38
httpd
security update
bug fix
oracle
mod_dav
mod_proxy
cve-2006-20001
cve-2022-37436
cve-2022-36760
EPSS
0.023
Percentile
90.0%
JSON
httpd
[2.4.37-51.0.1.1]
Set vstring per ORACLE_SUPPORT_PRODUCT [Orabug: 29892262]
Replace index.html with Oracle’s index page oracle_index.html
[2.4.37-51.1]
Resolves: #2165967 - prevent sscg creating /dhparams.pem
Resolves: #2165976 - CVE-2006-20001 httpd: mod_dav: out-of-bounds read/write
of zero byte
Resolves: #2165977 - CVE-2022-37436 httpd: mod_proxy: HTTP response splitting
Resolves: #2165978 - CVE-2022-36760 httpd: mod_proxy_ajp: Possible request
smuggling
Affected Package
OS
Version
Architecture
Package
Version
Filename
oracle linux
8
src
httpd
< 2.4.37-51.0.1.module
httpd-2.4.37-51.0.1.module+el8.7.0+20923+af3b70dd.1.src.rpm
oracle linux
8
src
mod_http2
< 1.15.7-5.module
mod_http2-1.15.7-5.module+el8.6.0+20548+01710940.src.rpm
oracle linux
8
src
mod_md
< 2.0.8-8.module
mod_md-2.0.8-8.module+el8.5.0+20475+4f6a8fd5.src.rpm
oracle linux
8
aarch64
httpd
< 2.4.37-51.0.1.module
httpd-2.4.37-51.0.1.module+el8.7.0+20923+af3b70dd.1.aarch64.rpm
oracle linux
8
aarch64
httpd-devel
< 2.4.37-51.0.1.module
httpd-devel-2.4.37-51.0.1.module+el8.7.0+20923+af3b70dd.1.aarch64.rpm
oracle linux
8
noarch
httpd-filesystem
< 2.4.37-51.0.1.module
httpd-filesystem-2.4.37-51.0.1.module+el8.7.0+20923+af3b70dd.1.noarch.rpm
oracle linux
8
noarch
httpd-manual
< 2.4.37-51.0.1.module
httpd-manual-2.4.37-51.0.1.module+el8.7.0+20923+af3b70dd.1.noarch.rpm
oracle linux
8
aarch64
httpd-tools
< 2.4.37-51.0.1.module
httpd-tools-2.4.37-51.0.1.module+el8.7.0+20923+af3b70dd.1.aarch64.rpm
oracle linux
8
aarch64
mod_http2
< 1.15.7-5.module
mod_http2-1.15.7-5.module+el8.6.0+20548+01710940.aarch64.rpm
oracle linux
8
aarch64
mod_ldap
< 2.4.37-51.0.1.module
mod_ldap-2.4.37-51.0.1.module+el8.7.0+20923+af3b70dd.1.aarch64.rpm
Rows per page:
10
1-10 of 28
1
Related
altlinux 2
openvas 34
nessus 59
ubuntu 3
almalinux 2
oraclelinux 1
fedora 2
rocky 2
osv 15
amazon 2
redos 1
redhat 6
freebsd 1
kaspersky 1
mageia 1
slackware 1
debian 2
ibm 13
gentoo 1
photon 2
prion 3
veracode 3
cvelist 3
vulnrichment 1
redhatcve 3
f5 3
nvd 3
cloudlinux 2
cve 3
alpinelinux 3
ubuntucve 3
cnvd 1
debiancve 3
cbl_mariner 4
broadcom 2
rosalinux 2
hp 1
qualysblog 1
ics 1
oracle 3
altlinux
altlinux
Security fix for the ALT Linux 9 package apache2 version 1:2.4.55-alt1
2023-02-16 00:00:00
Security fix for the ALT Linux 10 package apache2 version 1:2.4.55-alt1
2023-02-07 00:00:00
openvas
openvas
34
Huawei EulerOS: Security Advisory for httpd (EulerOS-SA-2023-2240)
2023-06-12 00:00:00
Fedora: Security Advisory for httpd (FEDORA-2023-f6ff3f85eb)
2023-01-29 00:00:00
SUSE: Security Advisory (SUSE-SU-2023:0321-1)
2023-02-10 00:00:00
nessus
nessus
59
Slackware Linux 14.0 / 14.1 / 14.2 / 15.0 / current httpd Multiple Vulnerabilities (SSA:2023-018-02)
2023-01-18 00:00:00
AlmaLinux 9 : httpd (ALSA-2023:0970)
2023-02-28 00:00:00
EulerOS Virtualization 2.10.1 : httpd (EulerOS-SA-2023-1901)
2023-05-16 00:00:00
ubuntu
ubuntu
Apache HTTP Server vulnerabilities
2023-02-01 00:00:00
Apache HTTP Server vulnerabilities
2023-01-31 00:00:00
Apache HTTP Server vulnerability
2023-02-02 00:00:00
almalinux
almalinux
Moderate: httpd:2.4 security and bug fix update
2023-02-21 00:00:00
Moderate: httpd security and bug fix update
2023-02-28 00:00:00
oraclelinux
oraclelinux
httpd security and bug fix update
2023-02-28 00:00:00
fedora
fedora
[SECURITY] Fedora 37 Update: httpd-2.4.55-1.fc37
2023-01-28 01:27:38
[SECURITY] Fedora 36 Update: httpd-2.4.55-1.fc36
2023-02-03 01:42:01
rocky
rocky
httpd security and bug fix update
2023-04-06 15:53:36
httpd:2.4 security and bug fix update
2023-02-22 01:08:53
osv
osv
15
apache2 vulnerabilities
2023-02-01 13:09:22
Moderate: httpd:2.4 security and bug fix update
2023-02-22 01:08:53
Moderate: httpd security and bug fix update
2023-04-06 15:53:36
amazon
amazon
Important: httpd
2023-02-17 00:10:00
Important: httpd24
2023-03-17 15:53:00
redos
redos
ROS-20240603-04
2024-06-03 00:00:00
redhat
redhat
6
(RHSA-2023:0970) Moderate: httpd security and bug fix update
2023-02-28 07:53:34
(RHSA-2023:0852) Moderate: httpd:2.4 security and bug fix update
2023-02-21 08:48:58
(RHSA-2023:4629) Moderate: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 security update
2023-08-15 17:35:29
freebsd
freebsd
Apache httpd -- Multiple vulnerabilities
2023-01-17 00:00:00
kaspersky
kaspersky
KLA20167 Multiple vulnerabilities in Apache HTTP Server
2023-01-17 00:00:00
mageia
mageia
Updated apache packages fix security vulnerability
2023-02-07 03:06:39
slackware
slackware
[slackware-security] httpd
2023-01-18 06:23:09
debian
debian
[SECURITY] [DLA 3351-1] apache2 security update
2023-03-03 16:35:17
[SECURITY] [DSA 5376-1] apache2 security update
2023-03-20 18:52:17
ibm
ibm
13
Security Bulletin: IBM HTTP Server (powered by Apache) for IBM i is vulnerable to HTTP response splitting and denial of service attacks (CVE-2022-37436, CVE-2006-20001)
2023-04-19 15:11:52
Security Bulletin: Vulnerability in Apache HTTP Server (CVE-2022-36760 and CVE-2022-37436 ) affects Power HMC
2023-06-20 09:31:46
Security Bulletin: Multiple security vulnerabilities has been identified in IBM HTTP Server shipped with IBM Rational ClearCase [CVE-2022-28331, CVE-2022-36760, CVE-2022-37436, CVE-2022-25147, CVE-2006-20001]
2023-03-03 06:30:57
gentoo
gentoo
Apache HTTPD: Multiple Vulnerabilities
2023-09-08 00:00:00
photon
photon
Critical Photon OS Security Update - PHSA-2023-3.0-0522
2023-01-31 00:00:00
Critical Photon OS Security Update - PHSA-2023-4.0-0325
2023-02-01 00:00:00
prion
prion
Design/Logic Flaw
2023-01-17 20:15:00
Code injection
2023-01-17 20:15:00
Design/Logic Flaw
2023-01-17 20:15:00
veracode
veracode
Denial Of Service (DoS)
2023-01-20 06:55:49
HTTP Response Splitting
2023-01-21 12:15:11
HTTP Request Smuggling
2023-01-23 12:46:08
cvelist
cvelist
CVE-2006-20001 Apache HTTP Server: mod_dav out of bounds read, or write of zero byte
2023-01-17 19:07:27
CVE-2022-37436 Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
2023-01-17 19:12:59
CVE-2022-36760 Apache HTTP Server: mod_proxy_ajp Possible request smuggling
2023-01-17 19:11:55
vulnrichment
vulnrichment
CVE-2006-20001 Apache HTTP Server: mod_dav out of bounds read, or write of zero byte
2023-01-17 19:07:27
redhatcve
redhatcve
CVE-2006-20001
2023-01-18 19:05:06
CVE-2022-37436
2023-01-18 19:05:38
CVE-2022-36760
2023-01-18 19:05:48
f5
f5
K000132525 : Apache vulnerability CVE-2006-20001
2023-02-14 00:00:00
K000132665 : Apache HTTPD vulnerability CVE-2022-37436
2023-02-22 00:00:00
K000132643 : Apache HTTP server vulnerability CVE-2022-36760
2023-02-22 00:00:00
nvd
nvd
CVE-2006-20001
2023-01-17 20:15:11
CVE-2022-37436
2023-01-17 20:15:11
CVE-2022-36760
2023-01-17 20:15:11
cloudlinux
cloudlinux
httpd: Fix of CVE-2006-20001
2023-03-06 21:06:33
httpd: Fix of CVE-2022-36760
2023-01-30 20:52:19
cve
cve
CVE-2006-20001
2023-01-17 20:15:11
CVE-2022-37436
2023-01-17 20:15:11
CVE-2022-36760
2023-01-17 20:15:11
alpinelinux
alpinelinux
CVE-2006-20001
2023-01-17 20:15:11
CVE-2022-37436
2023-01-17 20:15:11
CVE-2022-36760
2023-01-17 20:15:11
ubuntucve
ubuntucve
CVE-2006-20001
2023-01-17 00:00:00
CVE-2022-37436
2023-01-17 00:00:00
CVE-2022-36760
2023-01-17 00:00:00
cnvd
cnvd
Apache HTTP Server Buffer Overflow Vulnerability (CNVD-2023-80558)
2023-10-19 00:00:00
debiancve
debiancve
CVE-2006-20001
2023-01-17 20:15:11
CVE-2022-37436
2023-01-17 20:15:11
CVE-2022-36760
2023-01-17 20:15:11
cbl_mariner
cbl_mariner
4
CVE-2022-37436 affecting package httpd for versions less than 2.4.55-1
2023-02-14 20:36:06
CVE-2022-37436 affecting package httpd 2.4.54-1
2023-02-14 02:35:58
CVE-2022-36760 affecting package httpd 2.4.54-1
2023-02-14 02:35:58
broadcom
broadcom
mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
2023-06-12 00:00:00
CVE-2022-36760 - HTTP Request Smuggling
2023-05-02 00:00:00
rosalinux
rosalinux
Advisory ROSA-SA-2023-2161
2023-05-03 11:17:19
Advisory ROSA-SA-2023-2159
2023-04-25 11:49:15
hp
hp
HP Device Manager Security Updates
2023-04-13 00:00:00
qualysblog
qualysblog
Oracle Patch Tuesday April 2023 Security Update Review
2023-04-19 11:47:21
ics
ics
Siemens SCALANCE XCM-/XRM-300
2024-02-15 12:00:00
oracle
oracle
Oracle Critical Patch Update Advisory - July 2023
2023-07-18 00:00:00
Oracle Critical Patch Update Advisory - April 2023
2023-04-18 00:00:00
Oracle Critical Patch Update Advisory - October 2023
2023-10-17 00:00:00
EPSS
0.023
Percentile
90.0%
JSON
Related for ELSA-2023-0852
altlinux
2
openvas
34
nessus
59
ubuntu
3
almalinux
2
oraclelinux
1
fedora
2
rocky
2
osv
15
amazon
2
redos
1
redhat
6
freebsd
1
kaspersky
1
mageia
1
slackware
1
debian
2
ibm
13
gentoo
1
photon
2
prion
3
veracode
3
cvelist
3
vulnrichment
1
redhatcve
3
f5
3
nvd
3
cloudlinux
2
cve
3
alpinelinux
3
ubuntucve
3
cnvd
1
debiancve
3
cbl_mariner
4
broadcom
2
rosalinux
2
hp
1
qualysblog
1
ics
1
oracle
3