Lucene search

K
osvGoogleOSV:ALSA-2021:3816
HistoryOct 12, 2021 - 3:53 p.m.

Important: httpd:2.4 security update

2021-10-1215:53:03
Google
osv.dev
17
httpd
apache http server
security update
mod_proxy
ssrf
mod_session
heap overflow

AI Score

9.7

Confidence

High

EPSS

0.967

Percentile

99.7%

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: mod_proxy: SSRF via a crafted request uri-path containing “unix:” (CVE-2021-40438)

  • httpd: mod_session: Heap overflow via a crafted SessionHeader value (CVE-2021-26691)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.