Lucene search

K
oraclelinuxOracleLinuxELSA-2023-6365
HistoryNov 11, 2023 - 12:00 a.m.

mod_auth_openidc security and bug fix update

2023-11-1100:00:00
linux.oracle.com
4
mod_auth_openidc
security update
bug fix
auth_openidc.conf
cve-2023-28625
null pointer dereference

0.002 Low

EPSS

Percentile

61.3%

[2.4.9.4-4]
Resolves: rhbz#2189268 - auth_openidc.conf mode 0640 by default
[2.4.9.4-3]

  • Resolves: rhbz#2184145 - CVE-2023-28625 NULL pointer dereference
    when OIDCStripCookies is set and a crafted Cookie header is supplied
    [2.4.9.4-2]
  • Resolves: rhbz#2153656 - CVE-2022-23527 - Open Redirect in
    oidc_validate_redirect_url() using tab character