RHSA-2021:4257: Moderate: httpd:2.4 security, bug fix, and enhancement update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: modsession: NULL pointer dereference when parsing Cookie header (CVE-2021-26690) httpd: Unexpected URL matching with 'MergeSlashes OFF' (CVE-2021-30641) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-41.module+el8.5.0+11772+c8e0c271.aa - Upgrade
Upgrade
httpd:2.4 (RPM module package)to a version that resolves this vulnerability.Fixed in httpd-2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
mod_http2 (RPM module package)to a version that resolves this vulnerability.Fixed in mod_http2-1.15.7-3.module+el8.4.0+8625+d397f3da - Upgrade
Upgrade
mod_ldap (RPM module package)to a version that resolves this vulnerability.Fixed in mod_ldap-2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
mod_md (RPM module package)to a version that resolves this vulnerability.Fixed in mod_md-2.0.8-8.module+el8.3.0+6814+67d1e611 - Upgrade
Upgrade
mod_proxy_html (RPM module package)to a version that resolves this vulnerability.Fixed in mod_proxy_html-2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
mod_session (RPM module package)to a version that resolves this vulnerability.Fixed in mod_session-2.4.37-41.module+el8.5.0+11772+c8e0c271 - Upgrade
Upgrade
mod_ssl (RPM module package)to a version that resolves this vulnerability.Fixed in mod_ssl-2.4.37-41.module+el8.5.0+11772+c8e0c271
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:4257?
The severity of RHSA-2021:4257 is classified as moderate.
How do I fix RHSA-2021:4257?
To fix RHSA-2021:4257, update the httpd package to version 2.4.37-41.module+el8.5.0+11772+c8e0c271.
What vulnerabilities are addressed in RHSA-2021:4257?
RHSA-2021:4257 addresses vulnerabilities including a NULL pointer dereference in mod_session and unexpected URL matching when 'MergeSlashes' is set to OFF.
Which versions of httpd are affected by RHSA-2021:4257?
Versions of httpd before 2.4.37-41.module+el8.5.0+11772+c8e0c271 are affected by RHSA-2021:4257.
What software packages are related to RHSA-2021:4257?
RHSA-2021:4257 relates to the httpd, httpd-debuginfo, httpd-devel, and related packages.