RHSA-2019:2893: Important: httpd:2.4 security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): HTTP/2: request for large response leads to denial of service (CVE-2019-9517) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-12.module+el8.0.0+4096+eb40e6da.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2893?
The severity of RHSA-2019:2893 is classified as important due to the potential for denial of service.
How do I fix RHSA-2019:2893?
To fix RHSA-2019:2893, update the httpd package to version 2.4.37-12.module+el8.0.0+4096+eb40e6da or later.
What vulnerabilities does RHSA-2019:2893 address?
RHSA-2019:2893 addresses a vulnerability in HTTP/2 that allows for a denial of service when handling large responses.
What versions of httpd are affected by RHSA-2019:2893?
Versions of httpd prior to 2.4.37-12.module+el8.0.0+4096+eb40e6da are affected by RHSA-2019:2893.
What is the impact of the vulnerability in RHSA-2019:2893?
The impact of the vulnerability in RHSA-2019:2893 can lead to a denial of service, making the Apache HTTP Server unresponsive.