Lucene search

K
oraclelinuxOracleLinuxELSA-2024-4726
HistoryJul 23, 2024 - 12:00 a.m.

httpd security update

2024-07-2300:00:00
linux.oracle.com
7
httpd
security update
oracle index
mod_proxy
mod_rewrite
ssrf
null pointer

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

Low

EPSS

0.036

Percentile

91.8%

[2.4.57-11.0.1]

  • Replace index.html with Oracle’s index page oracle_index.html.
    [2.4.57-11]
  • Resolves: RHEL-45792 - httpd: Encoding problem in
    mod_proxy (CVE-2024-38473)
    [2.4.57-9]
  • Resolves: RHEL-45766 - httpd: null pointer dereference in
    mod_proxy (CVE-2024-38477)
  • Resolves: RHEL-45749 - httpd: Potential SSRF in mod_rewrite (CVE-2024-39573)
  • Resolves: RHEL-45818 - httpd: Substitution encoding issue in
    mod_rewrite (CVE-2024-38474)
  • Resolves: RHEL-45771 - httpd: Improper escaping of output in
    mod_rewrite (CVE-2024-38475)

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

Low

EPSS

0.036

Percentile

91.8%