Low: mod_http2 security update . {"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2024:8680","synopsis":"Low: mod_http2 security update","severity":"SEVERITY_LOW","topic":"An update is available for mod_http2.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.\n\nSecurity Fix(es):\n\n* mod_http2: DoS by null pointer in websocket over HTTP\/2 (CVE-2024-36387)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[{"ticket":"2295006","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2295006","description":""}],"cves":[{"name":"CVE-2024-36387","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-36387","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"}],"references":[],"publishedAt":"2024-11-08T15:57:59.128395Z","rpms":{"Rocky Linux 9":{"nvras":["mod_http2-0:2.0.26-2.el9_4.1.aarch64.rpm","mod_http2-0:2.0.26-2.el9_4.1.ppc64le.rpm","mod_http2-0:2.0.26-2.el9_4.1.s390x.rpm","mod_http2-0:2.0.26-2.el9_4.1.src.rpm","mod_http2-0:2.0.26-2.el9_4.1.x86_64.rpm","mod_http2-debuginfo-0:2.0.26-2.el9_4.1.aarch64.rpm","mod_http2-debuginfo-0:2.0.26-2.el9_4.1.ppc64le.rpm","mod_http2-debuginfo-0:2.0.26-2.el9_4.1.s390x.rpm","mod_http2-debuginfo-0:2.0.26-2.el9_4.1.x86_64.rpm","mod_http2-debugsource-0:2.0.26-2.el9_4.1.aarch64.rpm","mod_http2-debugsource-0:2.0.26-2.el9_4.1.ppc64le.rpm","mod_http2-debugsource-0:2.0.26-2.el9_4.1.s390x.rpm","mod_http2-debugsource-0:2.0.26-2.el9_4.1.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]} . Rocky Linux 9 applies a minorsecurity update for mod_http2 to mitigate Denial of Service vulnerabilities that impact the HTTP/2 protocol.. Rocky Linux, mod_http2, security update, DoS fix, HTTP/2 protocol. . Severity: Low. LinuxSecurity.com Team
chromium-browser: Use after free in ANGLE (CVE-2020-6463) * chromium-browser: Inappropriate implementation in WebRTC (CVE-2020-6514) * Mozilla: Potential leak of redirect targets when loading scripts in a worker (CVE-2020-15652) * Mozilla: Memory safety bugs fixed in Firefox 79 and Firefox ESR 68.11 (CVE-2020-15659) SL6 x86_64 firefox-68.11.0-1.el6_10.x86_64.rpm firefox-debuginfo [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2020:3233-1 Issue Date: 2020-07-30 CVE Numbers: None -- Security Fix(es): * chromium-browser: Use after free in ANGLE (CVE-2020-6463) * chromium-browser: Inappropriate implementation in WebRTC (CVE-2020-6514) * Mozilla: Potential leak of redirect targets when loading scripts in a worker (CVE-2020-15652) * Mozilla: Memory safety bugs fixed in Firefox 79 and Firefox ESR 68.11 (CVE-2020-15659) -- SL6 x86_64 firefox-68.11.0-1.el6_10.x86_64.rpm firefox-debuginfo-68.11.0-1.el6_10.x86_64.rpm firefox-68.11.0-1.el6_10.i686.rpm firefox-debuginfo-68.11.0-1.el6_10.i686.rpm i386 firefox-68.11.0-1.el6_10.i686.rpm firefox-debuginfo-68.11.0-1.el6_10.i686.rpm - Scientific Linux Development Team . The recent patch for Firefox on Scientific Linux tackles various critical vulnerabilities and issues linked to browser functionality and performance.. firefox security, Scientific Linux update, browser safety fix, web protocol issues. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.