REDHAT-BUG-2486414: Buffer Overflow
A buffer overflow in modproxyhtml in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apache-http-server/mod_proxy_htmlto a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2486414?
The severity of REDHAT-BUG-2486414 is rated high with a score of 7.
What is the vulnerability identified in REDHAT-BUG-2486414?
REDHAT-BUG-2486414 is a buffer overflow vulnerability in mod_proxy_html of Apache HTTP Server.
How do I fix REDHAT-BUG-2486414?
To fix REDHAT-BUG-2486414, upgrade to Apache HTTP Server version 2.4.68 or later.
What can be exploited due to REDHAT-BUG-2486414?
REDHAT-BUG-2486414 allows attacks by an untrusted backend due to the buffer overflow.
Which version of Apache HTTP Server is affected by REDHAT-BUG-2486414?
Apache HTTP Server versions 2.4.67 and earlier are affected by REDHAT-BUG-2486414.