Lucene search

K
oraclelinuxOracleLinuxELSA-2024-5193
HistoryAug 13, 2024 - 12:00 a.m.

httpd:2.4 security update

2024-08-1300:00:00
linux.oracle.com
13
httpd
update
security
mod_http2
cve-2024-38476
cve-2024-27316

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.018

Percentile

88.5%

httpd
[2.4.37-65.2.0.1]

  • Replace index.html with Oracle’s index page oracle_index.html
    [2.4.37-65.2]
  • Resolves: RHEL-46040 - httpd:2.4/httpd: Security issues via backend
    applications whose response headers are malicious or exploitable (CVE-2024-38476)
  • Resolves: RHEL-53022 - Regression introduced by CVE-2024-38474 fix
    mod_http2
    [1.15.7-10]
  • Resolves: RHEL-29817 - httpd:2.4/mod_http2: httpd: CONTINUATION frames
    DoS (CVE-2024-27316)
    mod_md

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7

Confidence

Low

EPSS

0.018

Percentile

88.5%