REDHAT-BUG-2486397: High severity Apache HTTP Server vulnerability
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2486397?
The severity of REDHAT-BUG-2486397 is rated high with a score of 7.
How do I fix REDHAT-BUG-2486397?
To fix REDHAT-BUG-2486397, users should upgrade Apache HTTP Server to version 2.4.68.
What type of vulnerability is REDHAT-BUG-2486397?
REDHAT-BUG-2486397 is a buffer over-read vulnerability affecting Apache HTTP Server.
Which versions of Apache HTTP Server are affected by REDHAT-BUG-2486397?
The affected versions of Apache HTTP Server are from 2.4.0 through 2.4.67.
What impact does REDHAT-BUG-2486397 have?
REDHAT-BUG-2486397 can allow an attacker-controlled OCSP server to exploit this vulnerability during outbound OCSP requests.