Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 430
Alerts This Week
Warning Icon 1 430

Debian 11: apache2 Critical Access Control Denial of Service DLA-4270-1

debian lts
Calendar Grey August 12, 2025
Scroller Debian Lts
Critical flaws identified in Apache, impacting SSL setups, necessitate immediate attention from Debian 11 bullseye users.
Multiple vulnerabilities have been addressed in Apache, a widely used web server

Summary

Please note that the fix for CVE-2025-23048, included in this DLA,
may cause some SSL-enabled websites to encounter the error AH02032.
Additional details are provided at the end of this advisory.

CVE-2024-42516

HTTP response splitting in the core of Apache HTTP Server allows an
attacker who can manipulate the Content-Type response headers of
applications hosted or proxied by the server can split the HTTP response

CVE-2024-43204

A SSRF (Server Side Request Forgery) was found in Apache HTTP Server
with mod_proxy loaded allows an attacker to
send outbound proxy requests to a URL controlled by the attacker.
This attack requires an unlikely configuration where mod_headers
is configured to modify the Content-Type request or response header with a
value provided in the HTTP request

CVE-2024-43394

A Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows
allows to potentially leak NTLM hashes to a malicious server via mod_rewrite

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: apache2
Version: 2.4.65-1~deb11u1
CVE ID: CVE-2024-42516 CVE-2024-43204 CVE-2024-43394 CVE-2024-47252

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.