Lucene search

K
redhatRedHatRHSA-2022:0143
HistoryJan 17, 2022 - 8:16 a.m.

(RHSA-2022:0143) Important: httpd security update

2022-01-1708:16:34
access.redhat.com
194

0.706 High

EPSS

Percentile

98.1%

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: mod_lua: Possible buffer overflow when parsing multipart content (CVE-2021-44790)

  • httpd: mod_session: Heap overflow via a crafted SessionHeader value (CVE-2021-26691)

  • httpd: NULL pointer dereference via malformed requests (CVE-2021-34798)

  • httpd: Out-of-bounds write in ap_escape_quotes() via malicious input (CVE-2021-39275)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.