Lucene search

K
oraclelinuxOracleLinuxELSA-2024-5138
HistoryAug 08, 2024 - 12:00 a.m.

httpd security update

2024-08-0800:00:00
linux.oracle.com
15
httpd
update
2.4.57
security
index.html
oracle
rhel-46047
cve-2024-38476
rhel-53021
regression

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.018

Percentile

88.5%

[2.4.57-11.0.1.el9_4.1]

  • Replace index.html with Oracle’s index page oracle_index.html.
    [2.4.57-11.1]
  • Resolves: RHEL-46047 - httpd: Security issues via backend applications whose
    response headers are malicious or exploitable (CVE-2024-38476)
  • Resolves: RHEL-53021 - Regression introduced by CVE-2024-38474 fix

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.018

Percentile

88.5%