REDHAT-BUG-2486395: Buffer Overflow
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apache-http-serverto a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2486395?
The severity of REDHAT-BUG-2486395 is medium, rated at 4.
What type of vulnerability is REDHAT-BUG-2486395?
REDHAT-BUG-2486395 is a heap-based buffer overflow vulnerability.
How do I fix REDHAT-BUG-2486395?
To fix REDHAT-BUG-2486395, users should upgrade Apache HTTP Server to version 2.4.68.
What versions of Apache HTTP Server are affected by REDHAT-BUG-2486395?
Apache HTTP Server versions from 2.4.0 to 2.4.67 are affected by REDHAT-BUG-2486395.
Is there a workaround for REDHAT-BUG-2486395?
There are no specific workarounds for REDHAT-BUG-2486395; the recommended solution is to upgrade to a secure version.