Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Fedora 35: 2021-3e8bcf2d2e Significant: Mod_Security Buffer Overflow Patch

fedora
Calendar Grey September 22, 2016
Dist Fedora Esm H88
Important enhancements for Apache mod_cluster address vulnerabilities that could be exploited from a distance while improving overall efficiency and security attributes.
Fixed remote exploits in Apache HTTP Server mod_manager and mod_proxy_cluster modules, fixed performance problems with shared memory, fixed thread pool off- by-one errors, enhanced...

Summary

Mod_cluster is an httpd-based load balancer. Like mod_jk and mod_proxy,

mod_cluster uses a communication channel to forward requests from httpd to one

of a set of application server nodes. Unlike mod_jk and mod_proxy, mod_cluster

leverages an additional connection between the application server nodes and

httpd. The application server nodes use this connection to transmit server-side

load balance factors and lifecycle events back to httpd via a custom set of

HTTP methods, affectionately called the Mod-Cluster Management Protocol (MCMP).

This additional feedback channel allows mod_cluster to offer a level of

intelligence and granularity not found in other load balancing solutions.

Update Information:

Fixed remote exploits in Apache HTTP Server mod_manager and mod_proxy_cluster modules, fixed performance problems with shared memory, fixed thread pool off- by-one errors, enhanced Tomcat 8 interoperability, fixed mod_proxy integration, added WebSockets proxy layer for mod_cluster.

Change Log

References


[ 1 ] Bug #1368613 - mod_cluster: Update to 1.3.3.Final https://bugzilla.redhat.com/show_bug.cgi?id=1368613

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update mod_cluster' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mod_cluster
Product: Fedora 24
Version: 1.3.3
Release: 8.fc24
Summary: Apache HTTP Server dynamic load balancer with Wildfly and Tomcat libraries

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here