REDHAT-BUG-2486402: High severity Apache HTTP Server vulnerability
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the modproxyftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Server (mod_proxy_ftp)to a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2486402?
The severity of REDHAT-BUG-2486402 is high, rated at 7.
What is the nature of the vulnerability in REDHAT-BUG-2486402?
REDHAT-BUG-2486402 is a Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module.
Which versions of Apache HTTP Server are affected by REDHAT-BUG-2486402?
The vulnerability affects Apache HTTP Server versions from 2.4.0 through 2.4.67.
How do I fix REDHAT-BUG-2486402?
To fix REDHAT-BUG-2486402, users are recommended to upgrade to Apache HTTP Server version 2.4.68.
Can an attacker exploit REDHAT-BUG-2486402?
Yes, REDHAT-BUG-2486402 can be exploited by an attacker through an attacker-controlled backend FTP server.