[CLSA-2023:1679943745] Fix CVE(s): CVE-2023-25690
Type:
security
Severity:
Critical
Release date:
2023-03-27 19:02:25 UTC
Description:
* SECURITY UPDATE: proxy configuration may trigger HTTP request smuggling attack - debian/patches/CVE-2023-25690.patch: don't forward invalid query strings - CVE-2023-25690
Updated packages:
  • apache2_2.4.18-2ubuntu3.17+tuxcare.els10_amd64.deb
    sha:158b168dcb23641e11ee7e5f72bbf36a2b183171
  • apache2-bin_2.4.18-2ubuntu3.17+tuxcare.els10_amd64.deb
    sha:8558a5eb432e4a96165dd597f03f92bdf43a2a4a
  • apache2-data_2.4.18-2ubuntu3.17+tuxcare.els10_all.deb
    sha:3114cf640407bba26228bd5a793de9e07b16ab51
  • apache2-dev_2.4.18-2ubuntu3.17+tuxcare.els10_amd64.deb
    sha:5dd9640a125c2aedfa0c7ebea46bf42ee3dd5c75
  • apache2-doc_2.4.18-2ubuntu3.17+tuxcare.els10_all.deb
    sha:b6a72797a54f63e7f2fd0092164a9cabfb1759dc
  • apache2-suexec-custom_2.4.18-2ubuntu3.17+tuxcare.els10_amd64.deb
    sha:5e5521c54f05f2ffa5b89a156ddfb93ef9209451
  • apache2-suexec-pristine_2.4.18-2ubuntu3.17+tuxcare.els10_amd64.deb
    sha:ab053c3287f180d8fb88bdde2ff3c7a30e8f8149
  • apache2-utils_2.4.18-2ubuntu3.17+tuxcare.els10_amd64.deb
    sha:8d0d2bbfafe3ee8bd537d7a8ab2ab61eca213a2a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.