[CLSA-2026:1767949942] httpd: Fix of CVE-2025-58098
Type:
security
Severity:
Critical
Release date:
2026-01-14 13:06:31 UTC
Description:
- CVE-2025-58098: fix passes the shell-escaped query string to #exec cmd="..." directives
Updated packages:
  • httpd-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:ee04ad61824a998c2d80815e880dd81ea98ea4097f45856611b62b49fb0cb5d7
  • httpd-devel-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:70951f4f0c7dbb74e0bd09182f1ee146c271dc36fa938b09c508a7c7854c7bd4
  • httpd-manual-2.4.6-99.0.5.el7_9.1.tuxcare.els7.noarch.rpm
    sha:79fca3e9d5ec7c67a43e620cbdb3666d4c0ac0794ee9e0d8520dc5f5842bc4bd
  • httpd-tools-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:9aefa33e267325ee25cfbf940d6e1e44402bbf60e4c19fa159908ebe010d7271
  • mod_ldap-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:4401b3cb069b356cce4e02f1331af193004cc96ae7970aa5117dd394e4f6fe35
  • mod_proxy_html-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:774de11f5ab9c962ec45960c427a0908ebb51d024f81ab9e1cd57b7e1795cf9c
  • mod_session-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:e7b68b2bebd78805d8ff63a1f5da14d1477a8dbccdf5ae677521d96f43653d8d
  • mod_ssl-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:55ca7de469db215751fdb448a91a7462629133e1bddab205c5a0b1421a2bca75
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.