Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
219

Rocky Linux 8 RLSA-2023:1673 Important: httpd Security Fix

Important: httpd:2.4 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:1673", "synopsis": "Important: httpd:2.4 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for mod_http2, mod_md, httpd, module.httpd, module.mod_md, module.mod_http2.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.\n\nSecurity Fix(es):\n\n* httpd: HTTP request splitting with mod_rewrite and mod_proxy (CVE-2023-25690)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2176209", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2176209", "description": ""}], "cves": [{"name": "CVE-2023-25690", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-25690", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-04-12T01:40:50.593087Z", "rpms": {"Rocky Linux 8": {"nvras": ["httpd-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "httpd-0:2.4.37-51.module+el8.7.0+1059+126e9251.src.rpm", "httpd-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "httpd-debuginfo-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "httpd-debuginfo-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "httpd-debugsource-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "httpd-debugsource-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "httpd-devel-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "httpd-devel-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm","httpd-filesystem-0:2.4.37-51.module+el8.7.0+1059+126e9251.noarch.rpm", "httpd-manual-0:2.4.37-51.module+el8.7.0+1059+126e9251.noarch.rpm", "httpd-tools-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "httpd-tools-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "httpd-tools-debuginfo-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "httpd-tools-debuginfo-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "mod_http2-0:1.15.7-5.module+el8.6.0+823+f143cee1.aarch64.rpm", "mod_http2-0:1.15.7-5.module+el8.6.0+823+f143cee1.src.rpm", "mod_http2-0:1.15.7-5.module+el8.6.0+823+f143cee1.x86_64.rpm", "mod_http2-debuginfo-0:1.15.7-5.module+el8.6.0+823+f143cee1.aarch64.rpm", "mod_http2-debuginfo-0:1.15.7-5.module+el8.6.0+823+f143cee1.x86_64.rpm", "mod_http2-debugsource-0:1.15.7-5.module+el8.6.0+823+f143cee1.aarch64.rpm", "mod_http2-debugsource-0:1.15.7-5.module+el8.6.0+823+f143cee1.x86_64.rpm", "mod_ldap-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "mod_ldap-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "mod_ldap-debuginfo-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "mod_ldap-debuginfo-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "mod_md-1:2.0.8-8.module+el8.5.0+695+1fa8055e.aarch64.rpm", "mod_md-1:2.0.8-8.module+el8.5.0+695+1fa8055e.src.rpm", "mod_md-1:2.0.8-8.module+el8.5.0+695+1fa8055e.x86_64.rpm", "mod_md-debuginfo-1:2.0.8-8.module+el8.5.0+695+1fa8055e.aarch64.rpm", "mod_md-debuginfo-1:2.0.8-8.module+el8.5.0+695+1fa8055e.x86_64.rpm", "mod_md-debugsource-1:2.0.8-8.module+el8.5.0+695+1fa8055e.aarch64.rpm", "mod_md-debugsource-1:2.0.8-8.module+el8.5.0+695+1fa8055e.x86_64.rpm", "mod_proxy_html-1:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "mod_proxy_html-1:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "mod_proxy_html-debuginfo-1:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "mod_proxy_html-debuginfo-1:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "mod_session-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm","mod_session-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "mod_session-debuginfo-0:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "mod_session-debuginfo-0:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "mod_ssl-1:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "mod_ssl-1:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm", "mod_ssl-debuginfo-1:2.4.37-51.module+el8.7.0+1059+126e9251.aarch64.rpm", "mod_ssl-debuginfo-1:2.4.37-51.module+el8.7.0+1059+126e9251.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Crucial notice regarding httpd:2.4 in Rocky Linux, tackling vulnerabilities. Upgrade immediately for improved security.. httpd Security Fix, Rocky Linux Advisory, Apache HTTP Server Update, Web Server Security Alert. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 12, 2023 Important Rocky Linux
91

Gentoo: GLSA-202308-15 Urgent Advisory on Apache HTTP Server RCE Risk

Multiple vulnerabilities have been discovered in Apache Webserver, the worst of which could result in remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202208-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Apache HTTPD: Multiple Vulnerabilities Date: August 14, 2022 Bugs: #813429, #816399, #816864, #829722, #835131, #850622 ID: 202208-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in Apache Webserver, the worst of which could result in remote code execution. Background ========= The Apache HTTP server is one of the most popular web servers on the Internet. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/apache-tools < 2.4.54 > = 2.4.54 2 www-servers/apache < 2.4.54 > = 2.4.54 Description ========== Multiple vulnerabilities have been discovered in Apache HTTPD. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Apache HTTPD users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-servers/apache-2.4.54" All Apache HTTPD tools users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-admin/apache-tools-2.4.54" References ========= [ 1 ] CVE-2021-33193 https://nvd.nist.gov/vuln/detail/CVE-2021-33193 [ 2 ] CVE-2021-34798 https://nvd.nist.gov/vuln/detail/CVE-2021-34798 [ 3 ] CVE-2021-36160 https://nvd.nist.gov/vuln/detail/CVE-2021-36160 [ 4 ] CVE-2021-39275 https://nvd.nist.gov/vuln/detail/CVE-2021-39275 [ 5 ] CVE-2021-40438 https://nvd.nist.gov/vuln/detail/CVE-2021-40438 [ 6 ] CVE-2021-41524 https://nvd.nist.gov/vuln/detail/CVE-2021-41524 [ 7 ] CVE-2021-41773 https://nvd.nist.gov/vuln/detail/CVE-2021-41773 [ 8 ] CVE-2021-42013 https://nvd.nist.gov/vuln/detail/CVE-2021-42013 [ 9 ] CVE-2021-44224 https://nvd.nist.gov/vuln/detail/CVE-2021-44224 [ 10 ] CVE-2021-44790 https://nvd.nist.gov/vuln/detail/CVE-2021-44790 [ 11 ] CVE-2022-22719 https://nvd.nist.gov/vuln/detail/CVE-2022-22719 [ 12 ] CVE-2022-22720 https://nvd.nist.gov/vuln/detail/CVE-2022-22720 [ 13 ] CVE-2022-22721 https://nvd.nist.gov/vuln/detail/CVE-2022-22721 [ 14 ] CVE-2022-23943 https://nvd.nist.gov/vuln/detail/CVE-2022-23943 [ 15 ] CVE-2022-26377 https://nvd.nist.gov/vuln/detail/CVE-2022-26377 [ 16 ] CVE-2022-28614 https://nvd.nist.gov/vuln/detail/CVE-2022-28614 [ 17 ] CVE-2022-28615 https://nvd.nist.gov/vuln/detail/CVE-2022-28615 [ 18 ] CVE-2022-29404 https://nvd.nist.gov/vuln/detail/CVE-2022-29404 [ 19 ] CVE-2022-30522 https://nvd.nist.gov/vuln/detail/CVE-2022-30522 [ 20 ] CVE-2022-30556 https://nvd.nist.gov/vuln/detail/CVE-2022-30556 [ 21 ] CVE-2022-31813 https://nvd.nist.gov/vuln/detail/CVE-2022-31813 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202208-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Delve into major vulnerabilities in Apache HTTPD outlined by Gentoo GLSA 202208-20, including severe remote code execution threats endangering system integrity. gentoo security, apache vulnerabilities, remote code, system update, system security. . LinuxSecurity.com Team

Calendar%202 Aug 13, 2022 Gentoo
197

Debian Wheezy DLA-1389-1 Moderate: Apache2 Denial of Service Fix

Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-15710 . Package : apache2 Version : 2.2.22-13+deb7u13 CVE ID : CVE-2017-15710 CVE-2018-1301 CVE-2018-1312 Debian Bug : Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-15710 Alex Nichols and Jakob Hirsch reported that mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, could cause an of bound write if supplied with a crafted Accept-Language header. This could potentially be used for a Denial of Service attack. CVE-2018-1301 Robert Swiecki reported that a specially crafted request could have crashed the Apache HTTP Server, due to an out of bound access after a size limit is reached by reading the HTTP header. CVE-2018-1312 Nicolas Daniels discovered that when generating an HTTP Digest authentication challenge, the nonce sent by mod_auth_digest to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an attacker without detection. For Debian 7 "Wheezy", these problems have been fixed in version 2.2.22-13+deb7u13. We recommend that you upgrade your apache2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple security flaws addressed in apache2 for Debian Wheezy. Update advised to maintain optimal security.. Debian Wheezy, Apache2 Denial of Service, Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 30, 2018 Important Debian LTS
98

Red Hat Enterprise Linux 6.7 RHSA-2017:3195-01 Important HTTPD Issues

An update for httpd is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: httpd security update Advisory ID: RHSA-2017:3195-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2017:3195 Issue date: 2017-11-13 CVE Names: CVE-2017-3167 CVE-2017-3169 CVE-2017-7679 CVE-2017-9788 CVE-2017-9798 ==================================================================== 1. Summary: An update for httpd is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux HPC Node EUS (v. 6.7) - x86_64 Red Hat Enterprise Linux HPC Node Optional EUS (v. 6.7) - noarch, x86_64 Red Hat Enterprise Linux Server EUS (v. 6.7) - i386, noarch, ppc64, s390x, x86_64 3. Description: The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): * It was discovered that the httpd's mod_auth_digest module did not properly initialize memory before using it when processing certain headersrelated to digest authentication. A remote attacker could possibly use this flaw to disclose potentially sensitive information or cause httpd child process to crash by sending specially crafted requests to a server. (CVE-2017-9788) * It was discovered that the use of httpd's ap_get_basic_auth_pw() API function outside ofthe authentication phase could lead to authentication bypass. A remote attacker could possibly use this flaw to bypass required authentication if the API was used incorrectly by one of the modules used by httpd. (CVE-2017-3167) * A NULL pointer dereference flaw was found in the httpd's mod_ssl module. A remote attacker could use this flaw to cause an httpd child process to crash if another module used by httpd called a certain API function during the processing of an HTTPS request. (CVE-2017-3169) * A buffer over-read flaw was found in the httpd's mod_mime module. A user permitted to modify httpd's MIME configuration could use this flaw to cause httpd child process to crash. (CVE-2017-7679) * A use-after-free flaw was found in the way httpd handled invalid and previously unregistered HTTP methods specified in the Limit directive used in an .htaccess file. A remote attacker could possibly use this flaw to disclose portions of the server memory, or cause httpd child process to crash. (CVE-2017-9798) Red Hat would like to thank Hanno Böck for reporting CVE-2017-9798. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1463194 - CVE-2017-3167 httpd: ap_get_basic_auth_pw() authentication bypass 1463197 - CVE-2017-3169 httpd: mod_ssl NULL pointer dereference 1463207 - CVE-2017-7679 httpd: mod_mime buffer overread 1470748 - CVE-2017-9788 httpd: Uninitialized memory reflection in mod_auth_digest 1490344 - CVE-2017-9798 httpd: Use-after-free by limiting unregistered HTTP method (Optionsbleed) 6. Package List: Red Hat Enterprise Linux HPC Node EUS (v. 6.7): Source: httpd-2.2.15-47.el6_7.5.src.rpm x86_64: httpd-2.2.15-47.el6_7.5.x86_64.rpm httpd-debuginfo-2.2.15-47.el6_7.5.x86_64.rpm httpd-tools-2.2.15-47.el6_7.5.x86_64.rpm Red Hat Enterprise Linux HPC Node OptionalEUS (v. 6.7): noarch: httpd-manual-2.2.15-47.el6_7.5.noarch.rpm x86_64: httpd-debuginfo-2.2.15-47.el6_7.5.i686.rpm httpd-debuginfo-2.2.15-47.el6_7.5.x86_64.rpm httpd-devel-2.2.15-47.el6_7.5.i686.rpm httpd-devel-2.2.15-47.el6_7.5.x86_64.rpm mod_ssl-2.2.15-47.el6_7.5.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 6.7): Source: httpd-2.2.15-47.el6_7.5.src.rpm i386: httpd-2.2.15-47.el6_7.5.i686.rpm httpd-debuginfo-2.2.15-47.el6_7.5.i686.rpm httpd-devel-2.2.15-47.el6_7.5.i686.rpm httpd-tools-2.2.15-47.el6_7.5.i686.rpm mod_ssl-2.2.15-47.el6_7.5.i686.rpm noarch: httpd-manual-2.2.15-47.el6_7.5.noarch.rpm ppc64: httpd-2.2.15-47.el6_7.5.ppc64.rpm httpd-debuginfo-2.2.15-47.el6_7.5.ppc.rpm httpd-debuginfo-2.2.15-47.el6_7.5.ppc64.rpm httpd-devel-2.2.15-47.el6_7.5.ppc.rpm httpd-devel-2.2.15-47.el6_7.5.ppc64.rpm httpd-tools-2.2.15-47.el6_7.5.ppc64.rpm mod_ssl-2.2.15-47.el6_7.5.ppc64.rpm s390x: httpd-2.2.15-47.el6_7.5.s390x.rpm httpd-debuginfo-2.2.15-47.el6_7.5.s390.rpm httpd-debuginfo-2.2.15-47.el6_7.5.s390x.rpm httpd-devel-2.2.15-47.el6_7.5.s390.rpm httpd-devel-2.2.15-47.el6_7.5.s390x.rpm httpd-tools-2.2.15-47.el6_7.5.s390x.rpm mod_ssl-2.2.15-47.el6_7.5.s390x.rpm x86_64: httpd-2.2.15-47.el6_7.5.x86_64.rpm httpd-debuginfo-2.2.15-47.el6_7.5.i686.rpm httpd-debuginfo-2.2.15-47.el6_7.5.x86_64.rpm httpd-devel-2.2.15-47.el6_7.5.i686.rpm httpd-devel-2.2.15-47.el6_7.5.x86_64.rpm httpd-tools-2.2.15-47.el6_7.5.x86_64.rpm mod_ssl-2.2.15-47.el6_7.5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-3167 https://access.redhat.com/security/cve/CVE-2017-3169 https://access.redhat.com/security/cve/CVE-2017-7679 https://access.redhat.com/security/cve/CVE-2017-9788 https://access.redhat.com/security/cve/CVE-2017-9798 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . Morecontact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFaCdiCXlSAg2UNWIIRAvvmAKCVryur6iT1hOTsK7RDTh0MM5cjhQCgsymk drT3wYD3x6Goki6ZoizfatE=2Epw -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important upgrade for Apache server from Red Hat addresses key vulnerabilities. Safeguard system security.. Red Hat Advisory,httpd update,security impact,Linux enterprise support. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 13, 2017 Important Red Hat
99

Slackware: 2017-180-03 Critical: Httpd Denial Of Service Risk Fix

New httpd packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] httpd (SSA:2017-180-03) New httpd packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/httpd-2.4.26-i586-1_slack14.2.txz: Upgraded. This update fixes security issues which may lead to an authentication bypass or a denial of service: important: ap_get_basic_auth_pw() Authentication Bypass CVE-2017-3167 important: mod_ssl Null Pointer Dereference CVE-2017-3169 important: mod_http2 Null Pointer Dereference CVE-2017-7659 important: ap_find_token() Buffer Overread CVE-2017-7668 important: mod_mime Buffer Overread CVE-2017-7679 For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-3167 https://www.cve.org/CVERecord?id=CVE-2017-3169 https://www.cve.org/CVERecord?id=CVE-2017-7659 https://www.cve.org/CVERecord?id=CVE-2017-7668 https://www.cve.org/CVERecord?id=CVE-2017-7679 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: Updated package for Slackware x86_64 13.0: Updated package for Slackware 13.1: Updated package for Slackware x86_64 13.1: Updated package for Slackware 13.37: Updated package for Slackware x86_64 13.37: Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updatedpackage for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: 3f00c09d7f7fc679c60edea24aa2e24f httpd-2.2.32-i486-1_slack13.0.txz Slackware x86_64 13.0 package: 398ee8c9e198e6f87dafa12092f52681 httpd-2.2.32-x86_64-1_slack13.0.txz Slackware 13.1 package: 6c07977ed9799064aef4ac18f9b45df1 httpd-2.2.32-i486-1_slack13.1.txz Slackware x86_64 13.1 package: 3a80ee6b2d459fe3b49476b205fa1472 httpd-2.2.32-x86_64-1_slack13.1.txz Slackware 13.37 package: ff470f6bbeb553d55a083ce023340dfd httpd-2.2.32-i486-1_slack13.37.txz Slackware x86_64 13.37 package: 65e42ac5f38385c935fdf6937d52e44e httpd-2.2.32-x86_64-1_slack13.37.txz Slackware 14.0 package: 145ed3cb94caf035f2399eede0ef05e3 httpd-2.4.26-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 9e48513a5508757dd856309dd7bc86ec httpd-2.4.26-x86_64-1_slack14.0.txz Slackware 14.1 package: 8ddfb545db9fd25ce9a8c25f468c93d1 httpd-2.4.26-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 48dcd26874858ce96d83b102e8117877 httpd-2.4.26-x86_64-1_slack14.1.txz Slackware 14.2 package: c5e9b0490d7c2dc29c04e288956ea3e6 httpd-2.4.26-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 1947fc3942e8716580c84cbd92c42329 httpd-2.4.26-x86_64-1_slack14.2.txz Slackware -current package: 231eee45f432bb10e8edd51d03cde20c n/httpd-2.4.26-i586-1.txz Slackware x86_64 -current package: 2326f05f1e51895956b419d682122cdd n/httpd-2.4.26-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg httpd-2.4.26-i586-1_slack14.2.txz Then, restart Apache httpd: # /etc/rc.d/rc.httpd stop # /etc/rc.d/rc.httpd start +-----+ . Recent updates for httpd packages tackle critical security flaws found in multiple versions of Slackware.. slackware security update, apache httpd fix, denial of service, authentication bypass. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 29, 2017 Critical Slackware
89

Fedora 24: Security Advisory for Apache HTTPD Update - DoS Risks

Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-d22f50d985 2016-12-24 22:56:52.910065 -------------------------------------------------------------------------------- Name : httpd Product : Fedora 24 Version : 2.4.25 Release : 1.fc24 URL : https://httpd.apache.org/ Summary : Apache HTTP Server Description : The Apache HTTP Server is a powerful, efficient, and extensible web server. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1406744 - CVE-2016-0736 httpd: Padding Oracle in Apache mod_session_crypto https://bugzilla.redhat.com/show_bug.cgi?id=1406744 [ 2 ] Bug #1406753 - CVE-2016-2161 httpd: DoS vulnerability in mod_auth_digest https://bugzilla.redhat.com/show_bug.cgi?id=1406753 [ 3 ] Bug #1406822 - CVE-2016-8743 httpd: Apache HTTP Request Parsing Whitespace Defects https://bugzilla.redhat.com/show_bug.cgi?id=1406822 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade httpd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical update for Fedora 24addresses multiple flaws in Nginx web server, enhancing overall system protection.. Fedora 24, Apache httpd, Security Fix, DoS Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 25, 2016 Critical Fedora
98

Red Hat Enterprise Linux 7: RHSA-2015:1742-01 Moderate DoS in Subversion

Updated subversion packages that fix multiple security issues are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: subversion security update Advisory ID: RHSA-2015:1742-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:1742.html Issue date: 2015-09-08 CVE Names: CVE-2015-0248 CVE-2015-0251 CVE-2015-3184 CVE-2015-3187 ==================================================================== 1. Summary: Updated subversion packages that fix multiple security issues are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. The mod_dav_svn module is used with the Apache HTTP Server to allow access to Subversion repositories via HTTP. An assertion failure flaw was found in the way the SVN serverprocessed certain requests with dynamically evaluated revision numbers. A remote attacker could use this flaw to cause the SVN server (both svnserve and httpd with the mod_dav_svn module) to crash. (CVE-2015-0248) It was found that the mod_authz_svn module did not properly restrict anonymous access to Subversion repositories under certain configurations when used with Apache httpd 2.4.x. This could allow a user to anonymously access files in a Subversion repository, which should only be accessible to authenticated users. (CVE-2015-3184) It was found that the mod_dav_svn module did not properly validate the svn:author property of certain requests. An attacker able to create new revisions could use this flaw to spoof the svn:author property. (CVE-2015-0251) It was found that when an SVN server (both svnserve and httpd with the mod_dav_svn module) searched the history of a file or a directory, it would disclose its location in the repository if that file or directory was not readable (for example, if it had been moved). (CVE-2015-3187) Red Hat would like to thank the Apache Software Foundation for reporting these issues. Upstream acknowledges Evgeny Kotkov of VisualSVN as the original reporter of CVE-2015-0248 and CVE-2015-0251, and C. Michael Pilato of CollabNet as the original reporter of CVE-2015-3184 and CVE-2015-3187 flaws. All subversion users should upgrade to these updated packages, which contain backported patches to correct these issues. After installing the updated packages, for the update to take effect, you must restart the httpd daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are serving Subversion repositories via the svn:// protocol. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1205138 - CVE-2015-0248 subversion: (mod_dav_svn) remote denial of servicewith certain requests with dynamically evaluated revision numbers1205140 - CVE-2015-0251 subversion: (mod_dav_svn) spoofing svn:author property values for new revisions 1247249 - CVE-2015-3184 subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4 1247252 - CVE-2015-3187 subversion: svn_repos_trace_node_locations() reveals paths hidden by authz 6. Package List: Red Hat Enterprise Linux Client Optional (v. 7): Source: subversion-1.7.14-7.el7_1.1.src.rpm x86_64: mod_dav_svn-1.7.14-7.el7_1.1.x86_64.rpm subversion-1.7.14-7.el7_1.1.i686.rpm subversion-1.7.14-7.el7_1.1.x86_64.rpm subversion-debuginfo-1.7.14-7.el7_1.1.i686.rpm subversion-debuginfo-1.7.14-7.el7_1.1.x86_64.rpm subversion-devel-1.7.14-7.el7_1.1.i686.rpm subversion-devel-1.7.14-7.el7_1.1.x86_64.rpm subversion-gnome-1.7.14-7.el7_1.1.i686.rpm subversion-gnome-1.7.14-7.el7_1.1.x86_64.rpm subversion-javahl-1.7.14-7.el7_1.1.i686.rpm subversion-javahl-1.7.14-7.el7_1.1.x86_64.rpm subversion-kde-1.7.14-7.el7_1.1.i686.rpm subversion-kde-1.7.14-7.el7_1.1.x86_64.rpm subversion-libs-1.7.14-7.el7_1.1.i686.rpm subversion-libs-1.7.14-7.el7_1.1.x86_64.rpm subversion-perl-1.7.14-7.el7_1.1.i686.rpm subversion-perl-1.7.14-7.el7_1.1.x86_64.rpm subversion-python-1.7.14-7.el7_1.1.x86_64.rpm subversion-ruby-1.7.14-7.el7_1.1.i686.rpm subversion-ruby-1.7.14-7.el7_1.1.x86_64.rpm subversion-tools-1.7.14-7.el7_1.1.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v.7): Source: subversion-1.7.14-7.el7_1.1.src.rpm x86_64: mod_dav_svn-1.7.14-7.el7_1.1.x86_64.rpm subversion-1.7.14-7.el7_1.1.i686.rpm subversion-1.7.14-7.el7_1.1.x86_64.rpm subversion-debuginfo-1.7.14-7.el7_1.1.i686.rpm subversion-debuginfo-1.7.14-7.el7_1.1.x86_64.rpm subversion-devel-1.7.14-7.el7_1.1.i686.rpm subversion-devel-1.7.14-7.el7_1.1.x86_64.rpm subversion-gnome-1.7.14-7.el7_1.1.i686.rpm subversion-gnome-1.7.14-7.el7_1.1.x86_64.rpm subversion-javahl-1.7.14-7.el7_1.1.i686.rpm subversion-javahl-1.7.14-7.el7_1.1.x86_64.rpm subversion-kde-1.7.14-7.el7_1.1.i686.rpm subversion-kde-1.7.14-7.el7_1.1.x86_64.rpm subversion-libs-1.7.14-7.el7_1.1.i686.rpm subversion-libs-1.7.14-7.el7_1.1.x86_64.rpm subversion-perl-1.7.14-7.el7_1.1.i686.rpm subversion-perl-1.7.14-7.el7_1.1.x86_64.rpm subversion-python-1.7.14-7.el7_1.1.x86_64.rpm subversion-ruby-1.7.14-7.el7_1.1.i686.rpm subversion-ruby-1.7.14-7.el7_1.1.x86_64.rpm subversion-tools-1.7.14-7.el7_1.1.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: subversion-1.7.14-7.el7_1.1.src.rpm ppc64: mod_dav_svn-1.7.14-7.el7_1.1.ppc64.rpm subversion-1.7.14-7.el7_1.1.ppc64.rpm subversion-debuginfo-1.7.14-7.el7_1.1.ppc.rpm subversion-debuginfo-1.7.14-7.el7_1.1.ppc64.rpm subversion-libs-1.7.14-7.el7_1.1.ppc.rpm subversion-libs-1.7.14-7.el7_1.1.ppc64.rpm s390x: mod_dav_svn-1.7.14-7.el7_1.1.s390x.rpm subversion-1.7.14-7.el7_1.1.s390x.rpm subversion-debuginfo-1.7.14-7.el7_1.1.s390.rpm subversion-debuginfo-1.7.14-7.el7_1.1.s390x.rpm subversion-libs-1.7.14-7.el7_1.1.s390.rpm subversion-libs-1.7.14-7.el7_1.1.s390x.rpm x86_64: mod_dav_svn-1.7.14-7.el7_1.1.x86_64.rpm subversion-1.7.14-7.el7_1.1.x86_64.rpm subversion-debuginfo-1.7.14-7.el7_1.1.i686.rpm subversion-debuginfo-1.7.14-7.el7_1.1.x86_64.rpm subversion-libs-1.7.14-7.el7_1.1.i686.rpm subversion-libs-1.7.14-7.el7_1.1.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: subversion-1.7.14-7.ael7b_1.1.src.rpm ppc64le: mod_dav_svn-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-debuginfo-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-libs-1.7.14-7.ael7b_1.1.ppc64le.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: subversion-1.7.14-7.el7_1.1.ppc.rpm subversion-debuginfo-1.7.14-7.el7_1.1.ppc.rpm subversion-debuginfo-1.7.14-7.el7_1.1.ppc64.rpm subversion-devel-1.7.14-7.el7_1.1.ppc.rpm subversion-devel-1.7.14-7.el7_1.1.ppc64.rpm subversion-gnome-1.7.14-7.el7_1.1.ppc.rpm subversion-gnome-1.7.14-7.el7_1.1.ppc64.rpm subversion-javahl-1.7.14-7.el7_1.1.ppc.rpm subversion-javahl-1.7.14-7.el7_1.1.ppc64.rpm subversion-kde-1.7.14-7.el7_1.1.ppc.rpm subversion-kde-1.7.14-7.el7_1.1.ppc64.rpm subversion-perl-1.7.14-7.el7_1.1.ppc.rpm subversion-perl-1.7.14-7.el7_1.1.ppc64.rpm subversion-python-1.7.14-7.el7_1.1.ppc64.rpm subversion-ruby-1.7.14-7.el7_1.1.ppc.rpm subversion-ruby-1.7.14-7.el7_1.1.ppc64.rpm subversion-tools-1.7.14-7.el7_1.1.ppc64.rpm s390x: subversion-1.7.14-7.el7_1.1.s390.rpm subversion-debuginfo-1.7.14-7.el7_1.1.s390.rpm subversion-debuginfo-1.7.14-7.el7_1.1.s390x.rpm subversion-devel-1.7.14-7.el7_1.1.s390.rpm subversion-devel-1.7.14-7.el7_1.1.s390x.rpm subversion-gnome-1.7.14-7.el7_1.1.s390.rpm subversion-gnome-1.7.14-7.el7_1.1.s390x.rpm subversion-javahl-1.7.14-7.el7_1.1.s390.rpm subversion-javahl-1.7.14-7.el7_1.1.s390x.rpm subversion-kde-1.7.14-7.el7_1.1.s390.rpm subversion-kde-1.7.14-7.el7_1.1.s390x.rpm subversion-perl-1.7.14-7.el7_1.1.s390.rpm subversion-perl-1.7.14-7.el7_1.1.s390x.rpm subversion-python-1.7.14-7.el7_1.1.s390x.rpm subversion-ruby-1.7.14-7.el7_1.1.s390.rpm subversion-ruby-1.7.14-7.el7_1.1.s390x.rpm subversion-tools-1.7.14-7.el7_1.1.s390x.rpm x86_64: subversion-1.7.14-7.el7_1.1.i686.rpm subversion-debuginfo-1.7.14-7.el7_1.1.i686.rpm subversion-debuginfo-1.7.14-7.el7_1.1.x86_64.rpm subversion-devel-1.7.14-7.el7_1.1.i686.rpm subversion-devel-1.7.14-7.el7_1.1.x86_64.rpm subversion-gnome-1.7.14-7.el7_1.1.i686.rpm subversion-gnome-1.7.14-7.el7_1.1.x86_64.rpm subversion-javahl-1.7.14-7.el7_1.1.i686.rpm subversion-javahl-1.7.14-7.el7_1.1.x86_64.rpm subversion-kde-1.7.14-7.el7_1.1.i686.rpm subversion-kde-1.7.14-7.el7_1.1.x86_64.rpm subversion-perl-1.7.14-7.el7_1.1.i686.rpm subversion-perl-1.7.14-7.el7_1.1.x86_64.rpm subversion-python-1.7.14-7.el7_1.1.x86_64.rpm subversion-ruby-1.7.14-7.el7_1.1.i686.rpm subversion-ruby-1.7.14-7.el7_1.1.x86_64.rpm subversion-tools-1.7.14-7.el7_1.1.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64le: subversion-debuginfo-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-devel-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-gnome-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-javahl-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-kde-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-perl-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-python-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-ruby-1.7.14-7.ael7b_1.1.ppc64le.rpm subversion-tools-1.7.14-7.ael7b_1.1.ppc64le.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: subversion-1.7.14-7.el7_1.1.src.rpm x86_64: mod_dav_svn-1.7.14-7.el7_1.1.x86_64.rpm subversion-1.7.14-7.el7_1.1.x86_64.rpm subversion-debuginfo-1.7.14-7.el7_1.1.i686.rpm subversion-debuginfo-1.7.14-7.el7_1.1.x86_64.rpm subversion-libs-1.7.14-7.el7_1.1.i686.rpm subversion-libs-1.7.14-7.el7_1.1.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: subversion-1.7.14-7.el7_1.1.i686.rpm subversion-debuginfo-1.7.14-7.el7_1.1.i686.rpm subversion-debuginfo-1.7.14-7.el7_1.1.x86_64.rpm subversion-devel-1.7.14-7.el7_1.1.i686.rpm subversion-devel-1.7.14-7.el7_1.1.x86_64.rpm subversion-gnome-1.7.14-7.el7_1.1.i686.rpm subversion-gnome-1.7.14-7.el7_1.1.x86_64.rpm subversion-javahl-1.7.14-7.el7_1.1.i686.rpm subversion-javahl-1.7.14-7.el7_1.1.x86_64.rpm subversion-kde-1.7.14-7.el7_1.1.i686.rpm subversion-kde-1.7.14-7.el7_1.1.x86_64.rpm subversion-perl-1.7.14-7.el7_1.1.i686.rpm subversion-perl-1.7.14-7.el7_1.1.x86_64.rpm subversion-python-1.7.14-7.el7_1.1.x86_64.rpm subversion-ruby-1.7.14-7.el7_1.1.i686.rpm subversion-ruby-1.7.14-7.el7_1.1.x86_64.rpm subversion-tools-1.7.14-7.el7_1.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2015-0248 https://access.redhat.com/security/cve/CVE-2015-0251 https://access.redhat.com/security/cve/CVE-2015-3184 https://access.redhat.com/security/cve/CVE-2015-3187 https://access.redhat.com/security/updates/classification/#moderate https://subversion.apache.org/security/CVE-2015-0248-advisory.txt https://subversion.apache.org/security/CVE-2015-3184-advisory.txt https://subversion.apache.org/security/CVE-2015-0251-advisory.txt https://subversion.apache.org/security/CVE-2015-3187-advisory.txt 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFV7t6+XlSAg2UNWIIRAivqAKCtV0lnW3RGFsCNsKIU9lBHeBk4UQCdE8/b KVJwbobNcmPzKule+9U7RnM=F2J4 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent updates for subversion address significant security flaws in Red Hat Enterprise Linux 7. Ensure your system is protected today.. Red Hat Security Update, Subversion Software, Linux Security Patch. . LinuxSecurity.com Team

Calendar%202 Sep 08, 2015 Red Hat
89

Fedora 21: 2015-9216 Critical: Httpd Security Update 2.4.12

Update to new version 2.4.12.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9216 2015-05-30 09:34:54 -------------------------------------------------------------------------------- Name : httpd Product : Fedora 21 Version : 2.4.12 Release : 1.fc21 URL : https://httpd.apache.org/ Summary : Apache HTTP Server Description : The Apache HTTP Server is a powerful, efficient, and extensible web server. -------------------------------------------------------------------------------- Update Information: Update to new version 2.4.12. -------------------------------------------------------------------------------- ChangeLog: * Fri May 29 2015 Jan Kaluza - 2.4.12-1 - update to new version 2.4.12 * Wed Dec 17 2014 Jan Kaluza - 2.4.10-15 - core: fix bypassing of mod_headers rules via chunked requests (CVE-2013-5704) - mod_cache: fix NULL pointer dereference on empty Content-Type (CVE-2014-3581) - mod_proxy_fcgi: fix a potential crash with long headers (CVE-2014-3583) - mod_lua: fix handling of the Require line when a LuaAuthzProvider is used in multiple Require directives with different arguments (CVE-2014-8109) * Tue Oct 14 2014 Joe Orton - 2.4.10-14 - require apr-util 1.5.x * Thu Sep 18 2014 Jan Kaluza - 2.4.10-13 - use NoDelay and DeferAcceptSec in httpd.socket -------------------------------------------------------------------------------- References: [ 1 ] Bug #1174077 - CVE-2014-8109 httpd: LuaAuthzProvider argument handling issue https://bugzilla.redhat.com/show_bug.cgi?id=1174077 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update httpd' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Update your Fedora 21 web server to incorporate the latest httpd version 2.4.12 along with essential security patches for enhanced protection.. Fedora 21, Apache HTTPD, Security Update, Software Patch, Web Server. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 02, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200