[CLSA-2026:1767950193] httpd: Fix of CVE-2025-58098
Type:
security
Severity:
Important
Release date:
2026-01-09 09:16:37 UTC
Description:
- CVE-2025-58098: fix passes the shell-escaped query string to #exec cmd="..." directives
Updated packages:
  • httpd-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:72690b8c1e00440b8ff6ee2f9c1c11e5e6a6b0f76f8b10d47d62386f797732da
  • httpd-devel-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:4fd8eaf368d8a9cdf409b075775bb6632c000e811880f3cc9a7e2c7f33187a5e
  • httpd-manual-2.4.6-99.0.5.el7_9.1.tuxcare.els7.noarch.rpm
    sha:310f3e3ca90375424e27ee274aec5a3fe72ac5145662d76aad32af9b825e3938
  • httpd-tools-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:a879b9576d90ceadc305ea02df5bfc3aadfe3006642372236b0b0127b667f7c4
  • mod_ldap-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:d3cc68142e6b8cfab1fe5d49093f9096fc39315ab182012f80876c1c73911e05
  • mod_proxy_html-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:8c742e0d336187ec4e095f3c978590bb6a52a9c336014615e38a3e64b420a911
  • mod_session-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:624e1900ea35d672c1bca362721aee1eefc1699766dbafe843de95774235c422
  • mod_ssl-2.4.6-99.0.5.el7_9.1.tuxcare.els7.x86_64.rpm
    sha:3793b915690f900e58f9b9095c2df45119adfeac2fa1646cecb2b44442a76f5a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.