Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 22: 2015-11689 Moderate: httpd Security Issues Fixed

fedora
Calendar Grey July 21, 2015
Dist Fedora Esm H88
Debian 9 introduces Nginx version 1.10.3, resolving severe vulnerabilities and bugs that impact performance.
Update to new version 2.4.16

Summary

The Apache HTTP Server is a powerful, efficient, and extensible

web server.

Update Information:

Update to new version 2.4.16. This update fixed various bugs as well as few security issues.

Change Log

* Wed Jul 15 2015 Jan Kaluza - 2.4.12-4 - update to 2.4.16 * Tue Jul 7 2015 Joe Orton - 2.4.12-3 - mod_ssl: use "localhost" in the dummy SSL cert if len(FQDN) > 59 chars* Wed Jun 17 2015 Fedora Release Engineering - 2.4.12-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild

References


[ 1 ] Bug #1243887 - CVE-2015-3183 httpd: chunk header parsing defect https://bugzilla.redhat.com/show_bug.cgi?id=1243887 [ 2 ] Bug #1243888 - CVE-2015-3185 httpd: replacement of ap_some_auth_required with new ap_some_authn_required and ap_force_authn https://bugzilla.redhat.com/show_bug.cgi?id=1243888 [ 3 ] Bug #1243891 - CVE-2015-0253 httpd: a crash with ErrorDocument 400 pointing to a local URL-path https://bugzilla.redhat.com/show_bug.cgi?id=1243891 [ 4 ] Bug #1202988 - CVE-2015-0228 httpd: Possible mod_lua crash due to websocket bug https://bugzilla.redhat.com/show_bug.cgi?id=1202988

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update httpd' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: httpd
Product: Fedora 22
Version: 2.4.16
Release: 1.fc22
Summary: Apache HTTP Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here