Lucene search

K
redhatRedHatRHSA-2024:3121
HistoryMay 22, 2024 - 6:35 a.m.

(RHSA-2024:3121) Moderate: httpd:2.4 security update

2024-05-2206:35:40
access.redhat.com
69
rhsa-2024-3121
moderate
apache http server
mod_macro
out-of-bounds read vulnerability
mod_http2
reset requests exhaust memory
cve-2023-31122
cve-2023-44487
cve-2023-45802
cvss score
red hat enterprise linux 8.10

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.9

Confidence

Low

EPSS

0.816

Percentile

98.4%

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: mod_macro: out-of-bounds read vulnerability (CVE-2023-31122)

  • mod_http2: reset requests exhaust memory (incomplete fix of CVE-2023-44487) (CVE-2023-45802)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.10 Release Notes linked from the References section.

Rows per page:
1-10 of 821

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.9

Confidence

Low

EPSS

0.816

Percentile

98.4%