[CLSA-2022:1643747448] Fix of CVE: CVE-2021-26690, CVE-2021-30641, CVE-2021-40438
Type:
security
Severity:
moderate
Release date:
2022-02-01
Description:
- CVE-2021-40438: mod_proxy: SSRF via a crafted request uri-path - CVE-2021-30641: MergeSlashes regression - CVE-2021-26690: mod_session NULL pointer dereference in parser
Updated packages:
  • httpd-manual-2.4.37-39.module_el8.4.0+2002+7519fa2d.1.tuxcare.els1.noarch.rpm
    sha:b8e82940b89209ce9bd12999ad9ca5a8864e2116
  • mod_http2-1.15.7-3.module_el8.4.0+2002+7519fa2d.x86_64.rpm
    sha:60cb4b31515c912225d183afefd937e0789709bc
  • mod_session-2.4.37-39.module_el8.4.0+2002+7519fa2d.1.tuxcare.els1.x86_64.rpm
    sha:0b2c24bd2f8d6f2c41264b26bf408aeb97e01d5f
  • mod_proxy_html-2.4.37-39.module_el8.4.0+2002+7519fa2d.1.tuxcare.els1.x86_64.rpm
    sha:15a4cb2ca7cd31be09f60d11a40cd083f0d9e47a
  • httpd-filesystem-2.4.37-39.module_el8.4.0+2002+7519fa2d.1.tuxcare.els1.noarch.rpm
    sha:a101d92ae5d44175e56a69551d554e94a698803b
  • mod_ldap-2.4.37-39.module_el8.4.0+2002+7519fa2d.1.tuxcare.els1.x86_64.rpm
    sha:5301b4a10043406d9619cdc7230fb11114d29fcb
  • mod_ssl-2.4.37-39.module_el8.4.0+2002+7519fa2d.1.tuxcare.els1.x86_64.rpm
    sha:862c31d507e9b23b2d27091639b56ca99eef77bf
  • httpd-devel-2.4.37-39.module_el8.4.0+2002+7519fa2d.1.tuxcare.els1.x86_64.rpm
    sha:04985e0469feb38bf2d9fa9f1c598f6a88fa7b2a
  • httpd-tools-2.4.37-39.module_el8.4.0+2002+7519fa2d.1.tuxcare.els1.x86_64.rpm
    sha:9c0594957dfd1dbd2a83fb89493aa4070432ad45
  • httpd-2.4.37-39.module_el8.4.0+2002+7519fa2d.1.tuxcare.els1.x86_64.rpm
    sha:1f7edcfad3a30cadf8178cd75952bd665108609c
  • mod_md-2.0.8-8.module_el8.4.0+2002+7519fa2d.x86_64.rpm
    sha:d0d23b53a61523314421608eb90bbbdeff070498
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.