Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA-4982-1 Critical: Apache2 Denial of Service Threats

debian
Calendar Grey October 8, 2021
Debian Logo
A new update for the Apache HTTP Server has been issued, addressing multiple vulnerabilities that could lead to denial of service (DoS) and mod_proxy configuration risks
Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service

Summary

Several vulnerabilities have been found in the Apache HTTP server, which
could result in denial of service. In addition a vulnerability was
discovered in mod_proxy with which an attacker could trick the server
to forward requests to arbitrary origin servers.

For the oldstable distribution (buster), these problems have been fixed
in version 2.4.38-3+deb10u6.

For the stable distribution (bullseye), these problems have been fixed in
version 2.4.51-1~deb11u1.

We recommend that you upgrade your apache2 packages.

For the detailed security status of apache2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/apache2

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: apache2
CVE ID: CVE-2021-34798 CVE-2021-36160 CVE-2021-39275 CVE-2021-40438

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here