• [gentoo-announce] [ GLSA 202309-01 ] Apache HTTPD: Multiple Vulnerabili

    From glsamaker@gentoo.org@21:1/5 to All on Fri Sep 8 21:40:01 2023
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202309-01
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Low
    Title: Apache HTTPD: Multiple Vulnerabilities
    Date: September 08, 2023
    Bugs: #891211, #900416
    ID: 202309-01

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Multiple vulnerabilities have been discovered in Apache HTTPD, the worst
    of which could result in denial of service.

    Background
    ==========

    The Apache HTTP server is one of the most popular web servers on the
    Internet.

    Affected packages
    =================

    Package Vulnerable Unaffected
    ------------------ ------------ ------------
    www-servers/apache < 2.4.56 >= 2.4.56

    Description
    ===========

    Multiple vulnerabilities have been discovered in Apache HTTPD. Please
    review the CVE identifiers referenced below for details.

    Impact
    ======

    Please review the referenced CVE identifiers for details.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All Apache HTTPD users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.56"

    References
    ==========

    [ 1 ] CVE-2006-20001
    https://nvd.nist.gov/vuln/detail/CVE-2006-20001
    [ 2 ] CVE-2022-36760
    https://nvd.nist.gov/vuln/detail/CVE-2022-36760
    [ 3 ] CVE-2022-37436
    https://nvd.nist.gov/vuln/detail/CVE-2022-37436
    [ 4 ] CVE-2023-25690
    https://nvd.nist.gov/vuln/detail/CVE-2023-25690
    [ 5 ] CVE-2023-27522
    https://nvd.nist.gov/vuln/detail/CVE-2023-27522

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202309-01

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2023 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmT7ciAACgkQFMQkOaVy +9mYIQ//YeFlD1hIUmC4pKO4ukmpBYOUA93ddiKfaZB8r4GwtnZWV23dF9sHtnyY TzeicBA6Vidn18Uc1JG4rAsnwAuIdRfgWEcP5kYGIUim0J43UCOy7OV7W6F5lzHt SPlkqko7XvcurxL3zyzpsawPHO8e9fF0/iT2c2byvRzxM7/ln4SEkFBhclfeLUTR E8qDPq4yKxyGkCx7D1MY1hZThha+QPgAZUJVKiAgVq8IKJvWD613NX7mPaIyv5Fw sd9Ysnl8blZS8VLENcuaQl2OKZ6w2elcbOCWRXesGpGeulwLi74IFzT/ajI5/sKd 76vm5taWXF3C+jlqfI5Pd+MozAzxOK79cvuZWZOzQPcCx4ZSrfMA80AgTtVuNyPZ bF7Ew1oF72ywnj1zcVXNDAk6espJJ1+8pTiTrFvJO0kAssaMlIdcFBNXSG+PxpkY UAf5V9NSbgKjAUsfTP1kpZWc1SCLviEvoyXrHS5tvyT/Sfyq+UYM4tSGg3xiUu8O 1rMbLvrSlLcAxHuq37WW0gpcI94ricx/45H8r5Md2ATR0jv6gRsmbRBCsdVtmcyc mXUNy5fDy/l/TgIDy6fcmwpah6rYuDSJH8P4/CehFbcOrxcakYk42egZ0TOooCwO FaZ/L4oKBQvL7Ljm0JuxtgnKnDb5W9QkKsBKPKqk8ls8xdHnSvw=
    =YPCQ
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)