Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Oracle Linux 9: ELSA-2025-15023 httpd Moderate Access Control Bypass

oracle
Calendar Grey September 3, 2025
Oracle Linux Logo Esm H88
Essential patches for Oracle Linux 9's httpd, with solutions targeting numerous weaknesses and reinforcing overall security.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

[2.4.62-4.0.1.4] - Replace index.html with Oracle's index page oracle_index.html. [2.4.62-4.4] - Resolves: RHEL-99949 - CVE-2025-49812 httpd: HTTP Session Hijack via a TLS upgrade [2.4.62-4.1] - Resolves: RHEL-99972 - CVE-2024-47252 httpd: insufficient escaping of user-supplied data in mod_ssl - Resolves: RHEL-99963 - CVE-2025-23048 httpd: access control bypass by trusted clients is possible using TLS 1.3 session resumption - Resolves: RHEL-102079 - stickysession field does not work when specifying it in the query parameter after upgrade to 9.5 [2.4.62-4] - Resolves: RHEL-66488 - Apache HTTPD no longer parse PHP files with unicode characters in the name [2.4.62-3] - Resolves: RHEL-68660 - RewriteRule proxying to UDS (unix domain socket) configured in .htaccess doesn't work on httpd-2.4.62-1 [2.4.62-2] - mod_ssl: fix loading keys via ENGINE API Resolves: RHEL-36755 [2.4.62-1] - new version 2.4.62 - Resolves: RHEL-52724 - Regression introduced by CVE-2024-38474 fix ...

Read the Full Advisory

SRPMs

http://oss.oracle.com/ol9/SRPMS-updates/httpd-2.4.62-4.0.1.el9_6.4.src.rpm

x86_64

httpd-2.4.62-4.0.1.el9_6.4.x86_64.rpm httpd-core-2.4.62-4.0.1.el9_6.4.x86_64.rpm httpd-devel-2.4.62-4.0.1.el9_6.4.x86_64.rpm httpd-filesystem-2.4.62-4.0.1.el9_6.4.noarch.rpm httpd-manual-2.4.62-4.0.1.el9_6.4.noarch.rpm httpd-tools-2.4.62-4.0.1.el9_6.4.x86_64.rpm mod_ldap-2.4.62-4.0.1.el9_6.4.x86_64.rpm mod_lua-2.4.62-4.0.1.el9_6.4.x86_64.rpm mod_proxy_html-2.4.62-4.0.1.el9_6.4.x86_64.rpm mod_session-2.4.62-4.0.1.el9_6.4.x86_64.rpm mod_ssl-2.4.62-4.0.1.el9_6.4.x86_64.rpm

aarch64

httpd-2.4.62-4.0.1.el9_6.4.aarch64.rpm httpd-core-2.4.62-4.0.1.el9_6.4.aarch64.rpm httpd-devel-2.4.62-4.0.1.el9_6.4.aarch64.rpm httpd-filesystem-2.4.62-4.0.1.el9_6.4.noarch.rpm httpd-manual-2.4.62-4.0.1.el9_6.4.noarch.rpm httpd-tools-2.4.62-4.0.1.el9_6.4.aarch64.rpm mod_ldap-2.4.62-4.0.1.el9_6.4.aarch64.rpm mod_lua-2.4.62-4.0.1.el9_6.4.aarch64.rpm mod_proxy_html-2.4.62-4.0.1.el9_6.4.aarch64.rpm mod_session-2.4.62-4.0.1.el9_6.4.aarch64.rpm mod_ssl-2.4.62-4.0.1.el9_6.4.aarch64.rpm

Related CVEs: CVE-2024-47252 CVE-2025-23048 CVE-2025-49812

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here