Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 7: 2020-0166 Moderate: Apache Redirect and Memory Security Issues

mageia
Calendar Grey April 15, 2020
Dist Mageia Esm H88
Recent updates to Apache packages address significant vulnerabilities in Mageia, impacting versions from 2.4.0 through 2.4.41.

Updated apache packages fix security vulnerabilities: In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential migh...

Summary

Updated apache packages fix security vulnerabilities:
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL (CVE-2020-1927).
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server (CVE-2020-1934).

References

- https://bugs.mageia.org/show_bug.cgi?id=26418

- - https://httpd.apache.org/security/vulnerabilities_24.html

- https://www.cve.org/CVERecord?id=CVE-2019-XXXX

Resolution

SRPMS

- 7/core/apache-2.4.43-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 15 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0166.html
Type: security
CVE: CVE-2019-XXXX

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here