[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2016:1420-01 -- Redhat httpd24-httpd

ID: oval:org.secpod.oval:def:505010Date: (C)2021-02-03   (M)2023-12-07
Class: PATCHFamily: unix




The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix: * It was discovered that httpd used the value of the Proxy header from HTTP requests to initialize the HTTP_PROXY environment variable for CGI scripts, which in turn was incorrectly used by certain HTTP client implementations to configure the proxy for outgoing HTTP requests. A remote attacker could possibly use this flaw to redirect HTTP requests performed by a CGI script to an attacker-controlled proxy via a malicious HTTP request. Note: After this update, httpd will no longer pass the value of the Proxy request header to scripts via the HTTP_PROXY environment variable. * A flaw was found in the way httpd performed client authentication using X.509 client certificates. When the HTTP/2 protocol was enabled, a remote attacker could use this flaw to access resources protected by certificate authentication without providing a valid client certificate. Red Hat would like to thank Scott Geary for reporting CVE-2016-5387 and Apache Software Foundation for reporting CVE-2016-4979. Upstream acknowledges Erki Aring as the original reporter of CVE-2016-4979. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. 5. Bugs fixed : 1352476 - CVE-2016-4979 httpd: X509 client certificate authentication bypass using HTTP/2 1353755 - CVE-2016-5387 Apache HTTPD: sets environmental variable based on user supplied Proxy request header 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server : Source: httpd24-httpd-2.4.18-11.el6.src.rpm noarch: httpd24-httpd-manual-2.4.18-11.el6.noarch.rpm x86_64: httpd24-httpd-2.4.18-11.el6.x86_64.rpm httpd24-httpd-debuginfo-2.4.18-11.el6.x86_64.rpm httpd24-httpd-devel-2.4.18-11.el6.x86_64.rpm httpd24-httpd-tools-2.4.18-11.el6.x86_64.rpm httpd24-mod_ldap-2.4.18-11.el6.x86_64.rpm httpd24-mod_proxy_html-2.4.18-11.el6.x86_64.rpm httpd24-mod_session-2.4.18-11.el6.x86_64.rpm httpd24-mod_ssl-2.4.18-11.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS : Source: httpd24-httpd-2.4.18-11.el6.src.rpm noarch: httpd24-httpd-manual-2.4.18-11.el6.noarch.rpm x86_64: httpd24-httpd-2.4.18-11.el6.x86_64.rpm httpd24-httpd-debuginfo-2.4.18-11.el6.x86_64.rpm httpd24-httpd-devel-2.4.18-11.el6.x86_64.rpm httpd24-httpd-tools-2.4.18-11.el6.x86_64.rpm httpd24-mod_ldap-2.4.18-11.el6.x86_64.rpm httpd24-mod_proxy_html-2.4.18-11.el6.x86_64.rpm httpd24-mod_session-2.4.18-11.el6.x86_64.rpm httpd24-mod_ssl-2.4.18-11.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS : Source: httpd24-httpd-2.4.18-11.el6.src.rpm noarch: httpd24-httpd-manual-2.4.18-11.el6.noarch.rpm x86_64: httpd24-httpd-2.4.18-11.el6.x86_64.rpm httpd24-httpd-debuginfo-2.4.18-11.el6.x86_64.rpm httpd24-httpd-devel-2.4.18-11.el6.x86_64.rpm httpd24-httpd-tools-2.4.18-11.el6.x86_64.rpm httpd24-mod_ldap-2.4.18-11.el6.x86_64.rpm httpd24-mod_proxy_html-2.4.18-11.el6.x86_64.rpm httpd24-mod_session-2.4.18-11.el6.x86_64.rpm httpd24-mod_ssl-2.4.18-11.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation : Source: httpd24-httpd-2.4.18-11.el6.src.rpm noarch: httpd24-httpd-manual-2.4.18-11.el6.noarch.rpm x86_64: httpd24-httpd-2.4.18-11.el6.x86_64.rpm httpd24-httpd-debuginfo-2.4.18-11.el6.x86_64.rpm httpd24-httpd-devel-2.4.18-11.el6.x86_64.rpm httpd24-httpd-tools-2.4.18-11.el6.x86_64.rpm httpd24-mod_ldap-2.4.18-11.el6.x86_64.rpm httpd24-mod_proxy_html-2.4.18-11.el6.x86_64.rpm httpd24-mod_session-2.4.18-11.el6.x86_64.rpm httpd24-mod_ssl-2.4.18-11.el6.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server : Source: httpd24-httpd-2.4.18-11.el7.src.rpm noarch: httpd24-httpd-manual-2.4.18-11.el7.noarch.rpm x86_64: httpd24-httpd-2.4.18-11.el7.x86_64.rpm httpd24-httpd-debuginfo-2.4.18-11.el7.x86_64.rpm httpd24-httpd-devel-2.4.18-11.el7.x86_64.rpm httpd24-httpd-tools-2.4.18-11.el7.x86_64.rpm httpd24-mod_ldap-2.4.18-11.el7.x86_64.rpm httpd24-mod_proxy_html-2.4.18-11.el7.x86_64.rpm httpd24-mod_session-2.4.18-11.el7.x86_64.rpm httpd24-mod_ssl-2.4.18-11.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS : Source: httpd24-httpd-2.4.18-11.el7.src.rpm noarch: httpd24-httpd-manual-2.4.18-11.el7.noarch.rpm x86_64: httpd24-httpd-2.4.18-11.el7.x86_64.rpm httpd24-httpd-debuginfo-2.4.18-11.el7.x86_64.rpm httpd24-httpd-devel-2.4.18-11.el7.x86_64.rpm httpd24-httpd-tools-2.4.18-11.el7.x86_64.rpm httpd24-mod_ldap-2.4.18-11.el7.x86_64.rpm httpd24-mod_proxy_html-2.4.18-11.el7.x86_64.rpm httpd24-mod_session-2.4.18-11.el7.x86_64.rpm httpd24-mod_ssl-2.4.18-11.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS : Source: httpd24-httpd-2.4.18-11.el7.src.rpm noarch: httpd24-httpd-manual-2.4.18-11.el7.noarch.rpm x86_64: httpd24-httpd-2.4.18-11.el7.x86_64.rpm httpd24-httpd-debuginfo-2.4.18-11.el7.x86_64.rpm httpd24-httpd-devel-2.4.18-11.el7.x86_64.rpm httpd24-httpd-tools-2.4.18-11.el7.x86_64.rpm httpd24-mod_ldap-2.4.18-11.el7.x86_64.rpm httpd24-mod_proxy_html-2.4.18-11.el7.x86_64.rpm httpd24-mod_session-2.4.18-11.el7.x86_64.rpm httpd24-mod_ssl-2.4.18-11.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation : Source: httpd24-httpd-2.4.18-11.el7.src.rpm noarch: httpd24-httpd-manual-2.4.18-11.el7.noarch.rpm x86_64: httpd24-httpd-2.4.18-11.el7.x86_64.rpm httpd24-httpd-debuginfo-2.4.18-11.el7.x86_64.rpm httpd24-httpd-devel-2.4.18-11.el7.x86_64.rpm httpd24-httpd-tools-2.4.18-11.el7.x86_64.rpm httpd24-mod_ldap-2.4.18-11.el7.x86_64.rpm httpd24-mod_proxy_html-2.4.18-11.el7.x86_64.rpm httpd24-mod_session-2.4.18-11.el7.x86_64.rpm httpd24-mod_ssl-2.4.18-11.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2016-4979 https://access.redhat.com/security/cve/CVE-2016-5387 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/security/vulnerabilities/httpoxy

Platform:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Product:
httpd24-httpd
Reference:
RHSA-2016:1420-01
CVE-2016-4979
CVE-2016-5387
CVE    2
CVE-2016-4979
CVE-2016-5387
CPE    4
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7.0
cpe:/a:apache:httpd24-httpd
...

© SecPod Technologies