Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 40: 2024-937be154d8 Moderate: Apache HTTPd Response Splitting Fix

fedora
Calendar Grey April 19, 2024
Dist Fedora Esm H88
The recent Fedora 40 release for Apache HTTP Server tackles critical security vulnerabilities and boosts performance through various enhancements and corrections.
This update includes httpd version 2.4.59, fixing various security issues and bugs

Summary

The Apache HTTP Server is a powerful, efficient, and extensible

web server.

Update Information:

This update includes httpd version 2.4.59, fixing various security issues and bugs. See for complete details of the changes in this release.

Change Log

* Mon Apr 15 2024 Joe Orton - 2.4.59-2 - mod_ssl: add DH param handling fix (r1916863) * Fri Apr 5 2024 Joe Orton - 2.4.59-1 - update to 2.4.59 * Thu Mar 28 2024 Joe Orton - 2.4.58-8 - rebuild to fix changelog ordering * Thu Mar 7 2024 Rahul Sundaram - 2.4.58-7 - Update Systemd security settings as part of https://fedoraproject.org/wiki/Changes/SystemdSecurityHardening - updated httpd.service(5) (Joe Orton) * Wed Jan 24 2024 Fedora Release Engineering - 2.4.58-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sat Jan 20 2024 Fedora Release Engineering - 2.4.58-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2273491 - CVE-2023-38709 httpd: HTTP response splitting https://bugzilla.redhat.com/show_bug.cgi?id=2273491 [ 2 ] Bug #2273499 - CVE-2024-24795 httpd: HTTP Response Splitting in multiple modules https://bugzilla.redhat.com/show_bug.cgi?id=2273499

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-937be154d8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: httpd
Product: Fedora 40
Version: 2.4.59
Release: 2.fc40
Summary: Apache HTTP Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here