[CLSA-2026:1767970357] httpd: Fix of CVE-2025-58098
Type:
security
Severity:
Important
Release date:
2026-01-09 14:54:44 UTC
Description:
- CVE-2025-58098: fix passes the shell-escaped query string to #exec cmd="..." directives
Updated packages:
  • httpd-2.4.6-99.0.5.el7.centos.1.tuxcare.els7.x86_64.rpm
    sha:f612e12a8894d28ec1af9341a91651f4a3497af6f7ff2f05d9a455bcf7b895d0
  • httpd-devel-2.4.6-99.0.5.el7.centos.1.tuxcare.els7.x86_64.rpm
    sha:d73dfb7926e96dd6f3321c25ef70746e103b0188add973db2da05900dff07bb9
  • httpd-manual-2.4.6-99.0.5.el7.centos.1.tuxcare.els7.noarch.rpm
    sha:d6a219a45a4e68734c86b78dea899f3edd695be7fe5edc0770ac2a8de07eec1c
  • httpd-tools-2.4.6-99.0.5.el7.centos.1.tuxcare.els7.x86_64.rpm
    sha:fbe6e1e623d992ad44438f3d29b0ee1eaeef26e721693b1deef486ca044f8444
  • mod_ldap-2.4.6-99.0.5.el7.centos.1.tuxcare.els7.x86_64.rpm
    sha:69e50f82e9b5f7da0d1d57890f00566ef6cd4d91bb0ee0a6e4ec9bdedfad5539
  • mod_proxy_html-2.4.6-99.0.5.el7.centos.1.tuxcare.els7.x86_64.rpm
    sha:4631fadfc8eab248630da8fbbeab4d178addb42e73d7e387d3aa2240a8bdb07d
  • mod_session-2.4.6-99.0.5.el7.centos.1.tuxcare.els7.x86_64.rpm
    sha:fcb96ea4bff0e0f70ef16a6688a7e8b8145a58649e754faafe596c3c1a32a15e
  • mod_ssl-2.4.6-99.0.5.el7.centos.1.tuxcare.els7.x86_64.rpm
    sha:1aa5c7b9de01213b543ba4bf8036f71688049a563359105898ce3527711483e3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.