Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Fedora 21: 2015-9216 Critical: Httpd Security Update 2.4.12

fedora
Calendar Grey June 2, 2015
Scroller Fedora
Update your Fedora 21 web server to incorporate the latest httpd version 2.4.12 along with essential security patches for enhanced protection.
Update to new version 2.4.12.

Summary

The Apache HTTP Server is a powerful, efficient, and extensible

web server.

Update Information:

Update to new version 2.4.12.

Change Log

* Fri May 29 2015 Jan Kaluza - 2.4.12-1 - update to new version 2.4.12 * Wed Dec 17 2014 Jan Kaluza - 2.4.10-15 - core: fix bypassing of mod_headers rules via chunked requests (CVE-2013-5704) - mod_cache: fix NULL pointer dereference on empty Content-Type (CVE-2014-3581) - mod_proxy_fcgi: fix a potential crash with long headers (CVE-2014-3583) - mod_lua: fix handling of the Require line when a LuaAuthzProvider is used in multiple Require directives with different arguments (CVE-2014-8109) * Tue Oct 14 2014 Joe Orton - 2.4.10-14 - require apr-util 1.5.x * Thu Sep 18 2014 Jan Kaluza - 2.4.10-13 - use NoDelay and DeferAcceptSec in httpd.socket

References


[ 1 ] Bug #1174077 - CVE-2014-8109 httpd: LuaAuthzProvider argument handling issue https://bugzilla.redhat.com/show_bug.cgi?id=1174077

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update httpd' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: httpd
Product: Fedora 21
Version: 2.4.12
Release: 1.fc21
Summary: Apache HTTP Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.