Lucene search

K
osvGoogleOSV:RLSA-2021:3816
HistoryOct 12, 2021 - 3:53 p.m.

Important: httpd:2.4 security update

2021-10-1215:53:03
Google
osv.dev
12

9.7 High

AI Score

Confidence

High

0.971 High

EPSS

Percentile

99.8%

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: mod_proxy: SSRF via a crafted request uri-path containing “unix:” (CVE-2021-40438)

  • httpd: mod_session: Heap overflow via a crafted SessionHeader value (CVE-2021-26691)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.