RHSA-2021:3816: Important: httpd:2.4 security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: modproxy: SSRF via a crafted request uri-path containing "unix:" (CVE-2021-40438) httpd: modsession: Heap overflow via a crafted SessionHeader value (CVE-2021-26691) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-39.module+el8.4.0+12865+a7065a39.1.aa - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch CVE-2021-26691 - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch CVE-2021-40438
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3816?
The severity of RHSA-2021:3816 is categorized as important.
How do I fix RHSA-2021:3816?
To fix RHSA-2021:3816, upgrade the httpd package to version 2.4.37-39.module+el8.4.0+12865+a7065a39.1 or later.
What vulnerabilities are addressed in RHSA-2021:3816?
RHSA-2021:3816 addresses SSRF and heap overflow vulnerabilities in the Apache HTTP Server.
Which software packages are affected by RHSA-2021:3816?
The affected software packages include httpd, httpd-filesystem, httpd-manual, and several others.
Is updating httpd sufficient for RHSA-2021:3816?
Yes, updating the httpd package to the specified version will remediate the vulnerabilities in RHSA-2021:3816.