Lucene search

K
osvGoogleOSV:ALSA-2021:1809
HistoryMay 18, 2021 - 6:08 a.m.

Moderate: httpd:2.4 security, bug fix, and enhancement update

2021-05-1806:08:34
Google
osv.dev
10
httpd
security fix
bug fix
enhancement
update
mod_session_cookie
mod_proxy_uwsgi
mod_http2
cve-2018-17199
cve-2020-11984
cve-2020-11993
almalinux
release notes

AI Score

9.8

Confidence

High

EPSS

0.011

Percentile

84.5%

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: mod_session_cookie does not respect expiry time (CVE-2018-17199)

  • httpd: mod_proxy_uwsgi buffer overflow (CVE-2020-11984)

  • httpd: mod_http2 concurrent pool usage (CVE-2020-11993)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.