RHSA-2022:0891: Moderate: httpd:2.4 security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: NULL pointer dereference via malformed requests (CVE-2021-34798) httpd: Out-of-bounds write in apescapequotes() via malicious input (CVE-2021-39275) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-43.module+el8.5.0+14370+51c6d843.2.aa - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Fixed in httpd-2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
mod_http2to a version that resolves this vulnerability.Fixed in mod_http2-1.15.7-3.module+el8.4.0+8625+d397f3da - Upgrade
Upgrade
mod_ldapto a version that resolves this vulnerability.Fixed in mod_ldap-2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
mod_mdto a version that resolves this vulnerability.Fixed in mod_md-2.0.8-8.module+el8.3.0+6814+67d1e611 - Upgrade
Upgrade
mod_proxy_htmlto a version that resolves this vulnerability.Fixed in mod_proxy_html-2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
mod_sessionto a version that resolves this vulnerability.Fixed in mod_session-2.4.37-43.module+el8.5.0+14370+51c6d843.2 - Upgrade
Upgrade
mod_sslto a version that resolves this vulnerability.Fixed in mod_ssl-2.4.37-43.module+el8.5.0+14370+51c6d843.2
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0891?
The severity of RHSA-2022:0891 is categorized as important due to vulnerabilities that could lead to denial of service.
How do I fix RHSA-2022:0891?
To fix RHSA-2022:0891, update affected packages to version 2.4.37-43.module+el8.5.0+14370+51c6d843.2 or later.
What vulnerabilities are addressed in RHSA-2022:0891?
RHSA-2022:0891 addresses CVE-2021-34798, which involves a NULL pointer dereference via malformed requests.
Which packages are affected by RHSA-2022:0891?
Affected packages include httpd, httpd-filesystem, httpd-manual, httpd-debuginfo, and several others.
Is immediate action required for RHSA-2022:0891?
Yes, immediate action is recommended to mitigate potential impact from the vulnerabilities addressed in RHSA-2022:0891.