ELBA-2023-3333

ELBA-2023-3333 - httpd bug fix update

Type:BUG
Severity:NA
Release Date:2023-05-29

Description


[2.4.6-99.1.0.1]
- mod_proxy: ap_proxy_http_request() to clear hop-by-hop first and
fixup last [CVE-2022-31813][Orabug: 34381850]
- mod_session: save one apr_strtok() [Orabug: 33338149][CVE-2021-26690]
- replace index.html with Oracle's index page oracle_index.html

[2.4.6-99.1]
- Resolves: #2190143 - mod_rewrite regression with CVE-2023-25690




Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) httpd-2.4.6-99.0.1.el7_9.1.src.rpm361f2b8e1c6c5d05ecdec7a5bc22c0b5-
httpd-2.4.6-99.0.1.el7_9.1.aarch64.rpm495c1358ce951bba9954f399eb9c9115-
httpd-devel-2.4.6-99.0.1.el7_9.1.aarch64.rpm4bc0e2b76cd506761a55189145c6df91-
httpd-manual-2.4.6-99.0.1.el7_9.1.noarch.rpmc212ea3dac609fb8068b2718fb419907-
httpd-tools-2.4.6-99.0.1.el7_9.1.aarch64.rpm3ca703a1e25b9bf4d889513db901b56a-
mod_ldap-2.4.6-99.0.1.el7_9.1.aarch64.rpm37683ac92f81c43daf64f2d7aab709d3-
mod_proxy_html-2.4.6-99.0.1.el7_9.1.aarch64.rpm507d103959a1352bd5e371187f78f193-
mod_session-2.4.6-99.0.1.el7_9.1.aarch64.rpm2fb821e4423901e4f38467f39c40427b-
mod_ssl-2.4.6-99.0.1.el7_9.1.aarch64.rpmcb34c1eb5012c0d8c2cc099035d28d5f-
Oracle Linux 7 (x86_64) httpd-2.4.6-99.0.1.el7_9.1.src.rpm361f2b8e1c6c5d05ecdec7a5bc22c0b5-
httpd-2.4.6-99.0.1.el7_9.1.x86_64.rpma6486e27b592339b3f90e50e3668e86e-
httpd-devel-2.4.6-99.0.1.el7_9.1.x86_64.rpm608408d44889ad4083099ef61f99e63f-
httpd-manual-2.4.6-99.0.1.el7_9.1.noarch.rpmc212ea3dac609fb8068b2718fb419907-
httpd-tools-2.4.6-99.0.1.el7_9.1.x86_64.rpm62044e47a99359e793bcde38ddb756d7-
mod_ldap-2.4.6-99.0.1.el7_9.1.x86_64.rpmcf9b08f4ef92b109a897ee608d4300ba-
mod_proxy_html-2.4.6-99.0.1.el7_9.1.x86_64.rpmfdf01c4632aaa4f16ea3e90aa6b559af-
mod_session-2.4.6-99.0.1.el7_9.1.x86_64.rpm0e5e19ec14fae3aa9f8c0706339b6083-
mod_ssl-2.4.6-99.0.1.el7_9.1.x86_64.rpm10a35492f3851271217832255db048db-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete