|
|
Log in / Subscribe / Register

Fedora alert FEDORA-2015-11792 (httpd)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 21 Update: httpd-2.4.16-1.fc21
Date:  Thu, 30 Jul 2015 00:52:03 +0000
Message-ID:  <20150730005205.F09EC61BF6F0@bastion01.phx2.fedoraproject.org>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-11792 2015-07-17 23:30:36 -------------------------------------------------------------------------------- Name : httpd Product : Fedora 21 Version : 2.4.16 Release : 1.fc21 URL : http://httpd.apache.org/ Summary : Apache HTTP Server Description : The Apache HTTP Server is a powerful, efficient, and extensible web server. -------------------------------------------------------------------------------- Update Information: Update to new version 2.4.16. This update fixed various bugs as well as few security issues. For full changelog, see http://www.apache.org/dist/httpd/CHANGES_2.4.16 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 17 2015 Jan Kaluza <jkaluza@redhat.com> - 2.4.16-1 - update to new version 2.4.16 * Fri May 29 2015 Jan Kaluza <jkaluza@redhat.com> - 2.4.12-1 - update to new version 2.4.12 * Wed Dec 17 2014 Jan Kaluza <jkaluza@redhat.com> - 2.4.10-15 - core: fix bypassing of mod_headers rules via chunked requests (CVE-2013-5704) - mod_cache: fix NULL pointer dereference on empty Content-Type (CVE-2014-3581) - mod_proxy_fcgi: fix a potential crash with long headers (CVE-2014-3583) - mod_lua: fix handling of the Require line when a LuaAuthzProvider is used in multiple Require directives with different arguments (CVE-2014-8109) * Tue Oct 14 2014 Joe Orton <jorton@redhat.com> - 2.4.10-14 - require apr-util 1.5.x * Thu Sep 18 2014 Jan Kaluza <jkaluza@redhat.com> - 2.4.10-13 - use NoDelay and DeferAcceptSec in httpd.socket -------------------------------------------------------------------------------- References: [ 1 ] Bug #1243887 - CVE-2015-3183 httpd: chunk header parsing defect https://bugzilla.redhat.com/show_bug.cgi?id=1243887 [ 2 ] Bug #1243888 - CVE-2015-3185 httpd: replacement of ap_some_auth_required with new ap_some_authn_required and ap_force_authn https://bugzilla.redhat.com/show_bug.cgi?id=1243888 [ 3 ] Bug #1243891 - CVE-2015-0253 httpd: NULL pointer dereference crash with ErrorDocument 400 pointing to a local URL-path https://bugzilla.redhat.com/show_bug.cgi?id=1243891 [ 4 ] Bug #1202988 - CVE-2015-0228 httpd: Possible mod_lua crash due to websocket bug https://bugzilla.redhat.com/show_bug.cgi?id=1202988 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update httpd' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds