Update Info

SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-2597


Security update for apache2


Type: security
Severity: important
Issued: 2024-07-23
Description:
This update for apache2 fixes the following issues:

- CVE-2024-36387: Fixed DoS by null pointer in websocket over HTTP/2 (bsc#1227272)
- CVE-2024-38475: Fixed improper escaping of output in mod_rewrite (bsc#1227268)
- CVE-2024-38476: Fixed server may use exploitable/malicious backend application output to run local handlers via internal redirect (bsc#1227269)


              

Packages


  • apache2-2.4.58-150600.5.18.1
  • apache2-event-2.4.58-150600.5.18.1