Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Apache HTTP Server.. ========================================================================== Ubuntu Security Notice USN-8571-1 July 20, 2026 apache2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server incorrectly handled certain memory operations in mod_authn_socache. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-33007) Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache HTTP Server had an HTTP response splitting vulnerability in multiple modules when used with untrusted or compromised backend servers. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-33523) Elhanan Haenel discovered that Apache HTTP Server incorrectly handled certain memory operations in mod_proxy_ajp. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-33857) Tianshuo Han and Jérôme Djouder discovered that Apache HTTP Server incorrectly handled certain string operations in mod_proxy_ajp. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-34032) It was discovered that Apache HTTP Server's mod_proxy_html module incorrectly handled certain content from an untrusted backend. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-34355) It was discovered that Apache HTTP Server incorrectly handled ProxyPassReverseCookie directives with a malicious backend server. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-34356) It was discovered that Apache HTTP Server's mod_dav_fsmodule incorrectly handled certain path operations. An authenticated user could possibly use this issue to manipulate trusted WebDAV property databases or cause a denial of service. (CVE-2026-42535) It was discovered that Apache HTTP Server's mod_xml2enc module incorrectly handled certain content from an untrusted backend. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-42536) It was discovered that Apache HTTP Server incorrectly handled response headers when multiple content languages were configured. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-43951) It was discovered that Apache HTTP Server incorrectly restricted certain file functions in expressions within .htaccess files. A local attacker with .htaccess write access could possibly use this issue to obtain sensitive information. (CVE-2026-44119) It was discovered that Apache HTTP Server's mod_ssl module incorrectly handled OCSP responses from an attacker-controlled server. A remote attacker could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2026-44185) It was discovered that Apache HTTP Server's mod_proxy_ftp module incorrectly handled responses from an attacker-controlled backend FTP server. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-44186) It was discovered that Apache HTTP Server incorrectly handled crafted regular expressions in the server configuration. An attacker could possibly use this issue to execute arbitrary code or cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-44631) It was discovered that Apache HTTP Server's mod_http2 module had a use-after-free vulnerability when file handles were exhausted. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2026-48913) Update instructions: The problem can be corrected byupdating your system to the following package versions: Ubuntu 20.04 LTS apache2 2.4.41-4ubuntu3.23+esm5 Available with Ubuntu Pro apache2-bin 2.4.41-4ubuntu3.23+esm5 Available with Ubuntu Pro apache2-dev 2.4.41-4ubuntu3.23+esm5 Available with Ubuntu Pro apache2-ssl-dev 2.4.41-4ubuntu3.23+esm5 Available with Ubuntu Pro apache2-suexec-custom 2.4.41-4ubuntu3.23+esm5 Available with Ubuntu Pro apache2-suexec-pristine 2.4.41-4ubuntu3.23+esm5 Available with Ubuntu Pro apache2-utils 2.4.41-4ubuntu3.23+esm5 Available with Ubuntu Pro libapache2-mod-md 2.4.41-4ubuntu3.23+esm5 Available with Ubuntu Pro libapache2-mod-proxy-uwsgi 2.4.41-4ubuntu3.23+esm5 Available with Ubuntu Pro Ubuntu 18.04 LTS apache2 2.4.29-1ubuntu4.27+esm10 Available with Ubuntu Pro apache2-bin 2.4.29-1ubuntu4.27+esm10 Available with Ubuntu Pro apache2-dev 2.4.29-1ubuntu4.27+esm10 Available with Ubuntu Pro apache2-ssl-dev 2.4.29-1ubuntu4.27+esm10 Available with Ubuntu Pro apache2-suexec-custom 2.4.29-1ubuntu4.27+esm10 Available with Ubuntu Pro apache2-suexec-pristine 2.4.29-1ubuntu4.27+esm10 Available with Ubuntu Pro apache2-utils 2.4.29-1ubuntu4.27+esm10 Available with Ubuntu Pro Ubuntu 16.04 LTS apache2 2.4.18-2ubuntu3.17+esm19 Available with Ubuntu Pro apache2-bin 2.4.18-2ubuntu3.17+esm19 Available with Ubuntu Pro apache2-dev 2.4.18-2ubuntu3.17+esm19 Available with Ubuntu Pro apache2-suexec-custom 2.4.18-2ubuntu3.17+esm19 Available with Ubuntu Pro apache2-suexec-pristine 2.4.18-2ubuntu3.17+esm19 Available with Ubuntu Pro apache2-utils 2.4.18-2ubuntu3.17+esm19 Available with Ubuntu Pro Ubuntu 14.04 LTS apache2 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-bin 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-dev 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-mpm-event 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-mpm-itk 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-mpm-prefork 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-mpm-worker 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-suexec 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-suexec-custom 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-suexec-pristine 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2-utils 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro apache2.2-bin 2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro libapache2-mod-macro 1:2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro libapache2-mod-proxy-html 1:2.4.7-1ubuntu4.22+esm14 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8571-1 CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913, CVE-2026-49975 . Critical updates for Apache HTTP Server vulnerabilities across Ubuntu versions enhance security in your environment.. Ubuntu security, Apache update, denial of service, security notice, Apache vulnerabilities. . Severity: Important. LinuxSecurity.com Team
USN-8338-1 introduced a regression in Apache HTTP Server. ========================================================================== Ubuntu Security Notice USN-8338-2 May 29, 2026 apache2 regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: USN-8338-1 introduced a regression in Apache HTTP Server Software Description: - apache2: Apache HTTP server Details: USN-8338-1 fixed vulnerabilities in Apache HTTP Server. The update introduced a regression that prevented mod_http2 from loading on Ubuntu 18.04 LTS. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that Apache HTTP Server incorrectly handled certain response headers. An attacker could possibly use this issue to perform HTTP response splitting attacks. This issue only affected Ubuntu 14.04 LTS. (CVE-2023-38709) Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2 implementation did not properly reclaim memory when streams were reset by clients. A remote attacker could possibly use this issue to cause Apache HTTP Server to consume resources, leading to a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-45802) Keran Mu and Jianjun Chen discovered that Apache HTTP Server incorrectly handled certain response headers. An attacker could possibly use this issue to perform HTTP response splitting attacks. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-24795) Orange Tsai discovered that Apache HTTP Server mod_proxy incorrectly handled URL encoding. A remote attacker could possibly use this issue to bypass authentication via crafted requests. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-38473) Orange Tsai discovered that Apache HTTP Server could be caused to perform server-side request forgery (SSRF) via malicious backend response headers. A remote attacker couldpossibly use this issue to conduct SSRF attacks or disclose sensitive information. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38476) Orange Tsai discovered that Apache HTTP Server mod_proxy did not properly handle certain null pointer conditions. A remote attacker could possibly use this issue to cause Apache HTTP Server to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38477) Orange Tsai discovered that Apache HTTP Server mod_rewrite could be made to perform server-side request forgery (SSRF) via unsafe RewriteRules. A remote attacker could possibly use this issue to conduct SSRF attacks. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-39573) It was discovered that Apache HTTP Server incorrectly handled certain response headers. An attacker could possibly use this issue to perform HTTP response splitting attacks. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-42516) It was discovered that Apache HTTP Server could be caused to perform server-side request forgery (SSRF) via mod_headers modifying Content-Type headers. A remote attacker could possibly use this issue to conduct SSRF attacks. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-43204) John Runyon discovered that Apache HTTP Server mod_ssl did not properly escape user-supplied data before writing log entries. A remote attacker could possibly use this issue to insert escape sequences into log files. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-47252) Robert Merget discovered that Apache HTTP Server with SSLEngine optional was vulnerable to HTTP desynchronisation attacks. An attacker in a privileged network position could possibly use this issue to hijack HTTP sessions. This issue only affected Ubuntu 14.04 LTS. (CVE-2025-49812) It was discovered that Apache HTTP Server mod_md had an integer overflow in the ACME certificate renewal backoff timer. An attacker could possibly use this issue to cause excessive certificaterenewal requests. This issue only affected Ubuntu 20.04 LTS. (CVE-2025-55753) Anthony Parfenov discovered that Apache HTTP Server with SSI enabled and mod_cgid passed shell-escaped query strings to #exec cmd directives. A remote attacker could possibly use this issue to perform command injection. (CVE-2025-58098) Mattias �sander discovered that Apache HTTP Server incorrectly gave precedence to environment variables from HTTP headers over server-calculated CGI variables. A remote attacker could possibly use this issue to influence the environment of CGI programs. (CVE-2025-65082) Mattias �sander discovered that Apache HTTP Server mod_userdir with suexec could be caused to run CGI scripts under an unexpected user ID via RequestHeader directives in .htaccess files. An attacker with .htaccess write access could possibly use this issue to bypass suexec user restrictions. (CVE-2025-66200) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS apache2 2.4.29-1ubuntu4.27+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8338-2 https://ubuntu.com/security/notices/USN-8338-1 https://bugs.launchpad.net/bugs/2154546 . Ubuntu addresses a crucial regression in Apache HTTP Server impacting LTS 18.04, resolving critical service interruptions.. Apache HTTP server, Ubuntu LTS, security issues, regression , denial of service. . Severity: Important. LinuxSecurity.com Team
Moderate: ruby:2.5 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:7025", "synopsis": "Moderate: ruby:2.5 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for rubygem-bson, module.rubygem-bundler, rubygem-bundler, rubygem-abrt, module.rubygem-mongo, module.rubygem-pg, rubygem-mysql2, module.rubygem-mysql2, ruby, module.rubygem-abrt, module.rubygem-bson, rubygem-pg, module.ruby, rubygem-mongo.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.\n\nSecurity Fix(es):\n\n* ruby/cgi-gem: HTTP response splitting in CGI (CVE-2021-33621)\n\n* ruby: Buffer overrun in String-to-Float conversion (CVE-2022-28739)\n\n* ruby: ReDoS vulnerability in URI (CVE-2023-28755)\n\n* ruby: ReDoS vulnerability in Time (CVE-2023-28756)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.9 Release Notes linked from the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2075687", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2075687", "description": ""}, {"ticket": "2149706", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2149706", "description": ""}, {"ticket": "2184059", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2184059", "description": ""}, {"ticket": "2184061", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2184061", "description": ""}],"cves": [{"name": "CVE-2021-33621", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-33621", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-113"}, {"name": "CVE-2022-28739", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-28739", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "6.2", "cwe": "CWE-125"}, {"name": "CVE-2023-28755", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28755", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-20"}, {"name": "CVE-2023-28756", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-28756", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "5.3", "cwe": "CWE-20"}], "references": [], "publishedAt": "2026-04-14T18:01:10.838937Z", "rpms": {"Rocky Linux 8": {"nvras": ["rubygem-mongo-0:2.5.1-2.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-mongo-0:2.5.1-2.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-mongo-doc-0:2.5.1-2.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-mysql2-0:0.4.10-4.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-mysql2-0:0.4.10-4.module+el8.9.0+1536+5f79634e.src.rpm", "ruby-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-0:2.5.9-111.module+el8.9.0+1536+5f79634e.src.rpm", "ruby-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "ruby-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "ruby-debugsource-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-debugsource-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-debugsource-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm","ruby-devel-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-devel-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-devel-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "ruby-doc-0:2.5.9-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-abrt-0:0.3.0-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-abrt-0:0.3.0-4.module+el8.5.0+738+032c9c02.noarch.rpm", "rubygem-abrt-0:0.3.0-4.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-abrt-0:0.3.0-4.module+el8.5.0+738+032c9c02.src.rpm", "rubygem-abrt-doc-0:0.3.0-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-abrt-doc-0:0.3.0-4.module+el8.5.0+738+032c9c02.noarch.rpm", "rubygem-bigdecimal-0:1.3.4-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bigdecimal-0:1.3.4-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-bigdecimal-0:1.3.4-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bigdecimal-debuginfo-0:1.3.4-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bigdecimal-debuginfo-0:1.3.4-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-bigdecimal-debuginfo-0:1.3.4-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bson-0:4.3.0-2.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bson-0:4.3.0-2.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-bson-0:4.3.0-2.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bson-debuginfo-0:4.3.0-2.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bson-debuginfo-0:4.3.0-2.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bson-debugsource-0:4.3.0-2.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-bson-debugsource-0:4.3.0-2.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-bson-doc-0:4.3.0-2.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-bundler-0:1.16.1-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-bundler-0:1.16.1-4.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-bundler-doc-0:1.16.1-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-did_you_mean-0:1.2.0-111.module+el8.9.0+1536+5f79634e.noarch.rpm","rubygem-io-console-0:0.4.6-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-io-console-0:0.4.6-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-io-console-0:0.4.6-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-io-console-debuginfo-0:0.4.6-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-io-console-debuginfo-0:0.4.6-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-io-console-debuginfo-0:0.4.6-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-json-0:2.1.0-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-json-0:2.1.0-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-json-0:2.1.0-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-json-debuginfo-0:2.1.0-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-json-debuginfo-0:2.1.0-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-json-debuginfo-0:2.1.0-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-minitest-0:5.10.3-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-mysql2-0:0.4.10-4.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-mysql2-debuginfo-0:0.4.10-4.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-mysql2-debuginfo-0:0.4.10-4.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-mysql2-debugsource-0:0.4.10-4.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-mysql2-debugsource-0:0.4.10-4.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-mysql2-doc-0:0.4.10-4.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-net-telnet-0:0.1.1-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-openssl-0:2.1.2-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-openssl-0:2.1.2-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-openssl-0:2.1.2-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-openssl-debuginfo-0:2.1.2-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-openssl-debuginfo-0:2.1.2-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-openssl-debuginfo-0:2.1.2-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-pg-0:1.0.0-3.module+el8.9.0+1536+5f79634e.aarch64.rpm","rubygem-pg-0:1.0.0-3.module+el8.9.0+1536+5f79634e.src.rpm", "rubygem-pg-0:1.0.0-3.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-pg-debuginfo-0:1.0.0-3.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-pg-debuginfo-0:1.0.0-3.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-pg-debugsource-0:1.0.0-3.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-pg-debugsource-0:1.0.0-3.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-pg-doc-0:1.0.0-3.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-power_assert-0:1.1.1-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-psych-0:3.0.2-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-psych-0:3.0.2-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-psych-0:3.0.2-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-psych-debuginfo-0:3.0.2-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "rubygem-psych-debuginfo-0:3.0.2-111.module+el8.9.0+1536+5f79634e.i686.rpm", "rubygem-psych-debuginfo-0:3.0.2-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "rubygem-rake-0:12.3.3-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-rdoc-0:6.0.1.1-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygems-0:2.7.6.3-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygems-devel-0:2.7.6.3-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-test-unit-0:3.2.7-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "rubygem-xmlrpc-0:0.3.0-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "ruby-irb-0:2.5.9-111.module+el8.9.0+1536+5f79634e.noarch.rpm", "ruby-libs-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-libs-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-libs-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm", "ruby-libs-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.aarch64.rpm", "ruby-libs-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.i686.rpm", "ruby-libs-debuginfo-0:2.5.9-111.module+el8.9.0+1536+5f79634e.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate ruby security updates for Rocky Linux address buffer overflow and HTTPresponse splitting vulnerabilities.. Rocky Linux ruby security patch updates, buffer overflow, HTTP response vulnerability, ruby security advisory. . LinuxSecurity.com Team
1.282 - Sanitize all user-supplied values before inserting into HTTP headers; Fixed CVE-2025-40927.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-47551b2aa2 2025-12-11 01:00:50.567604+00:00 -------------------------------------------------------------------------------- Name : perl-CGI-Simple Product : Fedora 42 Version : 1.282 Release : 1.fc42 URL : https://metacpan.org/release/CGI-Simple Summary : Simple totally OO CGI interface that is CGI.pm compliant Description : Simple totally OO CGI interface that is CGI.pm compliant. -------------------------------------------------------------------------------- Update Information: 1.282 - Sanitize all user-supplied values before inserting into HTTP headers; Fixed CVE-2025-40927. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 2 2025 Jitka Plesnikova - 1:1.282-1 - 1.282 bump (rhbz#2392359) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2391834 - CVE-2025-40927 perl-CGI-Simple: CGI::Simple versions 1.281 and earlier for Perl has a HTTP response splitting flaw [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2391834 [ 2 ] Bug #2392359 - Upgrade perl-CGI-Simple to 1.282 https://bugzilla.redhat.com/show_bug.cgi?id=2392359 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-47551b2aa2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
MGASA-2025-0301 - Updated apache packages fix security vulnerabilities. MGASA-2025-0301 - Updated apache packages fix security vulnerabilities Publication date: 18 Nov 2025 URL: https://advisories.mageia.org/MGASA-2025-0301.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-42516, CVE-2024-43204, CVE-2024-47252, CVE-2025-49630, CVE-2025-23048, CVE-2025-49812, CVE-2025-53020, CVE-2025-54090 Description: HTTP response splitting. (CVE-2024-42516) SSRF with mod_headers setting Content-Type header. (CVE-2024-43204) mod_ssl error log variable escaping. (CVE-2024-47252) mod_proxy_http2 denial of service. (CVE-2025-49630) mod_ssl access control bypass with session resumption. (CVE-2025-23048) mod_ssl TLS upgrade attack. (CVE-2025-49812) HTTP/2 DoS by Memory Increase. (CVE-2025-53020) 'RewriteCond expr' always evaluates to true in 2.4.64. (CVE-2025-54090) You will find the update delay sometimes causes a failure; just restart the service after the update. References: - https://bugs.mageia.org/show_bug.cgi?id=34464 - https://www.openwall.com/lists/oss-security/2025/07/10/2 - https://www.openwall.com/lists/oss-security/2025/07/10/3 - https://www.openwall.com/lists/oss-security/2025/07/10/4 - https://www.openwall.com/lists/oss-security/2025/07/10/6 - https://www.openwall.com/lists/oss-security/2025/07/10/7 - https://www.openwall.com/lists/oss-security/2025/07/10/8 - https://www.openwall.com/lists/oss-security/2025/07/10/9 - https://www.openwall.com/lists/oss-security/2025/07/10/10 - https://www.openwall.com/lists/oss-security/2025/07/24/2 - https://www.cve.org/CVERecord?id=CVE-2024-42516 - https://www.cve.org/CVERecord?id=CVE-2024-43204 - https://www.cve.org/CVERecord?id=CVE-2024-47252 - https://www.cve.org/CVERecord?id=CVE-2025-49630 - https://www.cve.org/CVERecord?id=CVE-2025-23048 - https://www.cve.org/CVERecord?id=CVE-2025-49812 - https://www.cve.org/CVERecord?id=CVE-2025-53020 - https://www.cve.org/CVERecord?id=CVE-2025-54090 SRPMS: - 9/core/apache-2.4.65-1.mga9 .Updated Apache packages fix important security issues including HTTP response splitting and a DoS threat on Mageia.. mageia advisory, apache update, security fix, http response splitting, DoS attack. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Apache HTTP Server.. ======================================================================= === Ubuntu Security Notice USN-7639-2 August 19, 2025 apache2 vulnerabilities ======================================================================= === A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: USN-7639-1 fixed several vulnerabilities in Apache. This update provides the corresponding update for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and addressed a regression fix (LP: #2119395). CVE-2025-49630 and CVE-2025-53020 only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: It was discovered that the Apache HTTP Server incorrectly handled certain Content-Type response headers. A remote attacker could possibly use this issue to perform HTTP response splitting attacks. (CVE-2024-42516) xiaojunjie discovered that the Apache HTTP Server mod_proxy module incorrectly handled certain requests. A remote attacker could possibly use this issue to send outbound proxy requests to an arbitrary URL. (CVE-2024-43204) John Runyon discovered that the Apache HTTP Server mod_ssl module incorrectly escaped certain data. A remote attacker could possibly use this issue to insert escape characters into log files. (CVE-2024-47252) Sven Hebrok, Felix Cramer, Tim Storm, Maximilian Radoy, and Juraj Somorovsky discovered that the Apache HTTP Server mod_ssl module incorrectly handled TLS 1.3 session resumption. A remote attacker could possibly use this issue to bypass access control. (CVE-2025- 23048) Anthony CORSIEZ discovered that the Apache HTTP Server mod_proxy_http2 module incorrectly handled missing host headers. A remote attacker could possibly use thisissue to cause the server to crash, resulting in a denial of service. (CVE-2025-49630) Robert Merget discovered that the Apache HTTP Server mod_ssl module incorrectly handled TLS upgrades. A remote attacker could possibly use this issue to hijack an HTTP session. This update removes the old "SSLEngine optional" configuration option, possibly requiring a configuration change in certain environments. (CVE-2025-49812) Gal Bar Nahum discovered that the Apache HTTP Server incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause the server to consume resources, leading to a denial of service. (CVE-2025-53020) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS apache2 2.4.41-4ubuntu3.23+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS apache2 2.4.29-1ubuntu4.27+esm6 Available with Ubuntu Pro Ubuntu 16.04 LTS apache2 2.4.18-2ubuntu3.17+esm16 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7639-2 https://ubuntu.com/security/notices/USN-7639-1 CVE-2024-42516, CVE-2024-43204, CVE-2024-47252, CVE-2025-23048, CVE-2025-49630, CVE-2025-49812, CVE-2025-53020, https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/2119395 . Essential security updates resolve various vulnerabilities in the Apache HTTP Server for Ubuntu distributions, boosting server protection.. Ubuntu security patch, Apache HTTP fix, Server vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
* bsc#1246169 * bsc#1246302 * bsc#1246303 * bsc#1246305 * bsc#1246306 . # Security update for apache2 Announcement ID: SUSE-SU-2025:02684-1 Release Date: 2025-08-04T15:07:40Z Rating: important References: * bsc#1246169 * bsc#1246302 * bsc#1246303 * bsc#1246305 * bsc#1246306 * bsc#1246307 * bsc#1246477 Cross-References: * CVE-2024-42516 * CVE-2024-43204 * CVE-2024-47252 * CVE-2025-23048 * CVE-2025-49630 * CVE-2025-49812 * CVE-2025-53020 CVSS scores: * CVE-2024-42516 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-42516 ( SUSE ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2024-42516 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-43204 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-43204 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2024-43204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-47252 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-47252 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-47252 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-23048 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-23048 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-23048 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-49630 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49630 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49630 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49812 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-49812 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2025-49812 ( NVD ): 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-53020 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-53020 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-53020 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves seven vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues: * CVE-2024-42516: Fixed HTTP response splitting. (bsc#1246477) * CVE-2024-43204: Fixed a SSRF when mod_proxy is loaded that allows an attacker to send outbound proxy requests to a URL controlled by them. (bsc#1246305) * CVE-2024-47252: Fixed insufficient escaping of user-supplied data in mod_ssl allows an untrusted SSL/TLS client to insert escape characters into log file. (bsc#1246303) * CVE-2025-23048: Fixed access control bypass by trusted clients through TLS 1.3 session resumption in some mod_ssl configurations. (bsc#1246302) * CVE-2025-49630: Fixed denial of service can be triggered by untrusted clients causing an assertion in mod_proxy_http2. (bsc#1246307) * CVE-2025-49812: Fixed Opossum Attack Application Layer Desynchronization using Opportunistic TLS. (bsc#1246169) * CVE-2025-53020: Fixed HTTP/2 denial of service due to late release of memory after effective lifetime. (bsc#1246306) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-2684=1 openSUSE-SLE-15.6-2025-2684=1 * BasesystemModule 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2684=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-2684=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-2684=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * apache2-event-debugsource-2.4.58-150600.5.35.1 * apache2-event-debuginfo-2.4.58-150600.5.35.1 * apache2-utils-debugsource-2.4.58-150600.5.35.1 * apache2-debugsource-2.4.58-150600.5.35.1 * apache2-prefork-debuginfo-2.4.58-150600.5.35.1 * apache2-utils-2.4.58-150600.5.35.1 * apache2-utils-debuginfo-2.4.58-150600.5.35.1 * apache2-event-2.4.58-150600.5.35.1 * apache2-devel-2.4.58-150600.5.35.1 * apache2-2.4.58-150600.5.35.1 * apache2-prefork-2.4.58-150600.5.35.1 * apache2-prefork-debugsource-2.4.58-150600.5.35.1 * apache2-worker-debugsource-2.4.58-150600.5.35.1 * apache2-worker-2.4.58-150600.5.35.1 * apache2-worker-debuginfo-2.4.58-150600.5.35.1 * apache2-debuginfo-2.4.58-150600.5.35.1 * openSUSE Leap 15.6 (noarch) * apache2-manual-2.4.58-150600.5.35.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-debugsource-2.4.58-150600.5.35.1 * apache2-prefork-debuginfo-2.4.58-150600.5.35.1 * apache2-prefork-2.4.58-150600.5.35.1 * apache2-2.4.58-150600.5.35.1 * apache2-prefork-debugsource-2.4.58-150600.5.35.1 * apache2-debuginfo-2.4.58-150600.5.35.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-event-debugsource-2.4.58-150600.5.35.1 * apache2-event-debuginfo-2.4.58-150600.5.35.1 * apache2-debugsource-2.4.58-150600.5.35.1 * apache2-event-2.4.58-150600.5.35.1 * apache2-debuginfo-2.4.58-150600.5.35.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-utils-debugsource-2.4.58-150600.5.35.1 * apache2-utils-debuginfo-2.4.58-150600.5.35.1 *apache2-utils-2.4.58-150600.5.35.1 * apache2-devel-2.4.58-150600.5.35.1 * apache2-worker-debugsource-2.4.58-150600.5.35.1 * apache2-worker-2.4.58-150600.5.35.1 * apache2-worker-debuginfo-2.4.58-150600.5.35.1 ## References: * https://www.suse.com/security/cve/CVE-2024-42516.html * https://www.suse.com/security/cve/CVE-2024-43204.html * https://www.suse.com/security/cve/CVE-2024-47252.html * https://www.suse.com/security/cve/CVE-2025-23048.html * https://www.suse.com/security/cve/CVE-2025-49630.html * https://www.suse.com/security/cve/CVE-2025-49812.html * https://www.suse.com/security/cve/CVE-2025-53020.html * https://bugzilla.suse.com/show_bug.cgi?id=1246169 * https://bugzilla.suse.com/show_bug.cgi?id=1246302 * https://bugzilla.suse.com/show_bug.cgi?id=1246303 * https://bugzilla.suse.com/show_bug.cgi?id=1246305 * https://bugzilla.suse.com/show_bug.cgi?id=1246306 * https://bugzilla.suse.com/show_bug.cgi?id=1246307 * https://bugzilla.suse.com/show_bug.cgi?id=1246477 . Vital OpenSSL security patch resolves multiple vulnerabilities on Fedora Linux to enhance system defenses.. SUSE Linux, Apache2 Security, Important Update, CVE Fixes. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Apache HTTP Server.. ========================================================================== Ubuntu Security Notice USN-7639-1 July 16, 2025 apache2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: It was discovered that the Apache HTTP Server incorrectly handled certain Content-Type response headers. A remote attacker could possibly use this issue to perform HTTP response splitting attacks. (CVE-2024-42516) xiaojunjie discovered that the Apache HTTP Server mod_proxy module incorrectly handled certain requests. A remote attacker could possibly use this issue to send outbound proxy requests to an arbitrary URL. (CVE-2024-43204) John Runyon discovered that the Apache HTTP Server mod_ssl module incorrectly escaped certain data. A remote attacker could possibly use this issue to insert escape characters into log files. (CVE-2024-47252) Sven Hebrok, Felix Cramer, Tim Storm, Maximilian Radoy, and Juraj Somorovsky discovered that the Apache HTTP Server mod_ssl module incorrectly handled TLS 1.3 session resumption. A remote attacker could possibly use this issue to bypass access control. (CVE-2025-23048) Anthony CORSIEZ discovered that the Apache HTTP Server mod_proxy_http2 module incorrectly handled missing host headers. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. (CVE-2025-49630) Robert Merget discovered that the Apache HTTP Server mod_ssl module incorrectly handled TLS upgrades. A remote attacker could possibly use this issue to hijack an HTTP session. This update removes the old "SSLEngine optional" configuration option, possibly requiring a configuration change in certain environments.(CVE-2025-49812) Gal Bar Nahum discovered that the Apache HTTP Server incorrectly handled certain memory operations. A remote attacker could possibly use this issue to cause the server to consume resources, leading to a denial of service. (CVE-2025-53020) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 apache2 2.4.63-1ubuntu1.1 Ubuntu 24.04 LTS apache2 2.4.58-1ubuntu8.7 Ubuntu 22.04 LTS apache2 2.4.52-1ubuntu4.15 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7639-1 CVE-2024-42516, CVE-2024-43204, CVE-2024-47252, CVE-2025-23048, CVE-2025-49630, CVE-2025-49812, CVE-2025-53020 Package Information: https://launchpad.net/ubuntu/+source/apache2/2.4.63-1ubuntu1.1 https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.7 https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.15 . Several vulnerabilities in Apache Server addressed in recent Ubuntu updates. Users advised to apply updates for maintaining system security and protection.. Apache Server Security, System Update, HTTP Server Vulnerabilities, Ubuntu Security Fixes. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.