Protect your Linux 7: Patch critical httpd buffer overflow now!
Summary
Important: httpd security update
Security Fixes
* httpd: mod_lua: Possible buffer overflow when parsing multipart content
(CVE-2021-44790)
* httpd: mod_session: Heap overflow via a crafted SessionHeader value
(CVE-2021-26691)
* httpd: NULL pointer dereference via malformed requests (CVE-2021-34798)
* httpd: Out-of-bounds write in ap_escape_quotes() via malicious input
(CVE-2021-39275)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
SL7
x86_64
httpd-2.4.6-97.el7_9.4.x86_64.rpm
httpd-debuginfo-2.4.6-97.el7_9.4.x86_64.rpm
httpd-devel-2.4.6-97.el7_9.4.x86_64.rpm
httpd-tools-2.4.6-97.el7_9.4.x86_64.rpm
mod_ldap-2.4.6-97.el7_9.4.x86_64.rpm
mod_proxy_html-2.4.6-97.el7_9.4.x86_64.rpm
mod_session-2.4.6-97.el7_9.4.x86_64.rpm
mod_ssl-2.4.6-97.el7_9.4.x86_64.rpm
noarch
httpd-manual-2.4.6-97.el7_9.4.noarch.rpm
- Scientific Linux Development Team