First published: Wed Jul 15 2015(Updated: )
Apache HTTP Server 2.4.16 release fixes the following issue: *) SECURITY: <a href="https://access.redhat.com/security/cve/CVE-2015-3185">CVE-2015-3185</a> (cve.mitre.org) Replacement of ap_some_auth_required (unusable in Apache httpd 2.4) with new ap_some_authn_required and ap_force_authn hook. [Ben Reser] External References: <a href="http://httpd.apache.org/security/vulnerabilities_24.html#2.4.16">http://httpd.apache.org/security/vulnerabilities_24.html#2.4.16</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jbcs-httpd24-httpd | <0:2.4.23-122.jbcs.el6 | 0:2.4.23-122.jbcs.el6 |
redhat/jbcs-httpd24-openssl | <1:1.0.2h-14.jbcs.el6 | 1:1.0.2h-14.jbcs.el6 |
redhat/jbcs-httpd24-httpd | <0:2.4.23-122.jbcs.el7 | 0:2.4.23-122.jbcs.el7 |
redhat/jbcs-httpd24-openssl | <1:1.0.2h-14.jbcs.el7 | 1:1.0.2h-14.jbcs.el7 |
redhat/httpd | <0:2.4.6-31.el7_1.1 | 0:2.4.6-31.el7_1.1 |
redhat/httpd24-httpd | <0:2.4.12-4.el6.2 | 0:2.4.12-4.el6.2 |
redhat/httpd24-httpd | <0:2.4.12-6.el7.1 | 0:2.4.12-6.el7.1 |
redhat/httpd | <2.4.16 | 2.4.16 |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =15.04 | |
Apache HTTP Server | =2.4.0 | |
Apache HTTP Server | =2.4.1 | |
Apache HTTP Server | =2.4.2 | |
Apache HTTP Server | =2.4.3 | |
Apache HTTP Server | =2.4.4 | |
Apache HTTP Server | =2.4.6 | |
Apache HTTP Server | =2.4.7 | |
Apache HTTP Server | =2.4.8 | |
Apache HTTP Server | =2.4.9 | |
Apache HTTP Server | =2.4.10 | |
Apache HTTP Server | =2.4.12 | |
Apache HTTP Server | =2.4.13 | |
Apple Xcode | =7.0 | |
Apple Mac OS X | =10.10.4 | |
Apple Mac OS X Server | =5.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)