Lucene search

K
oraclelinuxOracleLinuxELSA-2023-1593
HistoryApr 05, 2023 - 12:00 a.m.

httpd security update

2023-04-0500:00:00
linux.oracle.com
39
httpd
security update
mod_proxy
mod_session
index.html
cve-2022-31813
orabug
cve-2021-26690
resolves
http request splitting
mod_rewrite

0.007 Low

EPSS

Percentile

81.0%

[2.4.6-98.0.3]

  • mod_proxy: ap_proxy_http_request() to clear hop-by-hop first and
    fixup last [CVE-2022-31813][Orabug: 34381850]
  • mod_session: save one apr_strtok() [Orabug: 33338149][CVE-2021-26690]
    [2.4.6-98.0.1]
  • replace index.html with Oracle’s index page oracle_index.html
    [2.4.6-97.7]
  • Resolves: #2177742 - CVE-2023-25690 httpd: HTTP request splitting with
    mod_rewrite and mod_proxy