[CLSA-2025:1757501175] httpd: Fix of CVE-2025-49812
Type:
security
Severity:
Important
Release date:
2025-09-10 10:46:19 UTC
Description:
- CVE-2025-49812: remove support for TLS upgrade to prevent HTTP desynchronisation attacks in mod_ssl configurations
Updated packages:
  • httpd-2.4.53-11.el9_2.5.tuxcare.els8.x86_64.rpm
    sha:dd0db42ac5d252fa86b04d2bcfbe0cda3236b067d17b83203c89b22718e8c19b
  • httpd-core-2.4.53-11.el9_2.5.tuxcare.els8.x86_64.rpm
    sha:055647ad083719a4adaa8f8e682d9d4e8272f66ffde47c136f7d690761a490f4
  • httpd-devel-2.4.53-11.el9_2.5.tuxcare.els8.x86_64.rpm
    sha:c6c6a436fa58f0c6005d9fddddd076fca9b323d7b0dbe2ae946364d707d58063
  • httpd-filesystem-2.4.53-11.el9_2.5.tuxcare.els8.noarch.rpm
    sha:b4c750afeef0313ce2bad04893407f9b2e1a56ef842f5082acdbe4df803ac672
  • httpd-manual-2.4.53-11.el9_2.5.tuxcare.els8.noarch.rpm
    sha:ac12b0772dc0cd354e93af7a2cd058419d47a0efec23b1c1969f5f0eff2b271a
  • httpd-tools-2.4.53-11.el9_2.5.tuxcare.els8.x86_64.rpm
    sha:39957b0c57be5e18fe7b675838e74f825f257a03d4044d6b98dc2beb4353968b
  • mod_ldap-2.4.53-11.el9_2.5.tuxcare.els8.x86_64.rpm
    sha:88f847498d235d77bf3907ff2a7ca92d760486dd9d877dcb966757003954578d
  • mod_lua-2.4.53-11.el9_2.5.tuxcare.els8.x86_64.rpm
    sha:2c3da38bda227fef42e10175fc897b2178572790d49ef9c84674c9f2b4f05c54
  • mod_proxy_html-2.4.53-11.el9_2.5.tuxcare.els8.x86_64.rpm
    sha:c095cc6c730e826b59c1a83343c4c15cf454378c4a5a7329cc4dab2466272f04
  • mod_session-2.4.53-11.el9_2.5.tuxcare.els8.x86_64.rpm
    sha:ac36f1ac539a5dec4fdd8c17d57adb1459b745284f99758d37c4a9ba9461b425
  • mod_ssl-2.4.53-11.el9_2.5.tuxcare.els8.x86_64.rpm
    sha:20a5d34b0071c80bdbacee4819c2ea284b19031668e15f1f0b5d83b640e999ad
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.