RHSA-2020:4751: Moderate: httpd:2.4 security, bug fix, and enhancement update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.The following packages have been upgraded to a later upstream version: modhttp2 (1.15.7). (BZ#1814236)Security Fix(es): httpd: memory corruption on early pushes (CVE-2019-10081) httpd: read-after-free in h2 connection shutdown (CVE-2019-10082) httpd: null-pointer dereference in modremoteip (CVE-2019-10097) httpd: modrewrite configurations vulnerable to open redirect (CVE-2020-1927) httpd: modhttp2: DoS via slow, unneeded request bodies (CVE-2018-17189) httpd: modhttp2: read-after-free on a string compare (CVE-2019-0196) httpd: modhttp2: possible crash on late upgrade (CVE-2019-0197) httpd: limited cross-site scripting in modproxy error page (CVE-2019-10092) httpd: modrewrite potential open redirect (CVE-2019-10098) httpd: modproxyftp use of uninitialized value (CVE-2020-1934) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-30.module+el8.3.0+7001+0766b9e7.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4751?
The severity of RHSA-2020:4751 is classified as important due to a memory corruption issue in the Apache HTTP Server.
How do I fix RHSA-2020:4751?
To fix RHSA-2020:4751, upgrade the httpd package to version 2.4.37-30.module+el8.3.0+7001+0766b9e7 or later.
What systems are affected by RHSA-2020:4751?
RHSA-2020:4751 affects Red Hat Enterprise Linux 8 systems using the Apache HTTP Server httpd package.
What specific components are impacted by RHSA-2020:4751?
RHSA-2020:4751 specifically impacts the httpd package and related modules, such as mod_http2.
Was a patch released for RHSA-2020:4751?
Yes, a patch for RHSA-2020:4751 was released to address the memory corruption vulnerability.