REDHAT-BUG-2464941: Medium severity Apache HTTP Server vulnerability
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.67
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2464941?
The severity of REDHAT-BUG-2464941 is classified as medium (4).
How do I fix REDHAT-BUG-2464941?
To fix REDHAT-BUG-2464941, upgrade to Apache HTTP Server version 2.4.67 or later.
What is REDHAT-BUG-2464941 about?
REDHAT-BUG-2464941 is about an escalation of privilege vulnerability in Apache HTTP Server that allows local .htaccess authors to read files with httpd user privileges.
What versions of Apache are affected by REDHAT-BUG-2464941?
Apache HTTP Server versions 2.4.66 and earlier are affected by REDHAT-BUG-2464941.
Who is impacted by REDHAT-BUG-2464941?
Local .htaccess authors using affected versions of Apache HTTP Server may be impacted by REDHAT-BUG-2464941.