[CLSA-2025:1767004508] httpd: Fix of CVE-2025-58098
Type:
security
Severity:
Important
Release date:
2025-12-29 10:35:12 UTC
Description:
- CVE-2025-58098: prevent command injection in mod_cgid via shell-escaped SSI query strings
Updated packages:
  • httpd-2.4.53-11.el9_2.5.tuxcare.els9.x86_64.rpm
    sha:3b9586dd079381c81995fafb6f2b0d03a24baa5365f59053cb83c132f3da2859
  • httpd-core-2.4.53-11.el9_2.5.tuxcare.els9.x86_64.rpm
    sha:d0c77fd13279e90013e29acfbb1d7c9186f95a74c5c34830a4cad4eca8eec4eb
  • httpd-devel-2.4.53-11.el9_2.5.tuxcare.els9.x86_64.rpm
    sha:ce69ab3e051e4474ccedb8263df763940eedc98b1ca30e3f7b0159f5ab55e566
  • httpd-filesystem-2.4.53-11.el9_2.5.tuxcare.els9.noarch.rpm
    sha:f7b1527e0d2b4b60e85cc74fe583d1faded2d2bc53da6281c018c9862584d2f5
  • httpd-manual-2.4.53-11.el9_2.5.tuxcare.els9.noarch.rpm
    sha:8a5ac5bbef2a95ca3e080d7c003e88a153a1468bbc15cd6406c433656119076c
  • httpd-tools-2.4.53-11.el9_2.5.tuxcare.els9.x86_64.rpm
    sha:ec637c838b64b0a6a8dfd32bf077c6bbe6bcd63bfbd654d52ac3f71dcd6db0f1
  • mod_ldap-2.4.53-11.el9_2.5.tuxcare.els9.x86_64.rpm
    sha:e4f30d9ecd3ae36812ba47f8a610091a310c5db937ede6af3927fc105ec10f01
  • mod_lua-2.4.53-11.el9_2.5.tuxcare.els9.x86_64.rpm
    sha:8ea8c2005ecce21ef83873e0b5684624274e29acd6745d1eaeb95760cec5e2b5
  • mod_proxy_html-2.4.53-11.el9_2.5.tuxcare.els9.x86_64.rpm
    sha:23ac4fc00920885fc2ba0b08bb4657db8a4b594717b8d70c0d41d8fac6ecb222
  • mod_session-2.4.53-11.el9_2.5.tuxcare.els9.x86_64.rpm
    sha:74a96458ca48d669ed0221b4d5b818befba9be7707acc5ed4121e55aaffc2694
  • mod_ssl-2.4.53-11.el9_2.5.tuxcare.els9.x86_64.rpm
    sha:ecd3f19824efde3aaa7b0988a74c81f72f4947c7bef56cc4323a12297a0f4fbb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.