Apache 2.4.61 HTTP serverinin zəifliklərinin aradan qaldırılması ilə buraxılışı.

Apache HTTP server 2.4.61 has been released, which was published shortly after the release of 2.4.60 and includes a fix for a regression change that caused a vulnerability (CVE-2024-39884) allowing exposure of script code processed via the AddType directive (for example, a specially formatted request to a PHP script can display its contents instead of executing it).

Version 2.4.60 of Apache httpd fixed 8 vulnerabilities, of which 5 are marked as critical, and introduced 13 changes. The identified vulnerabilities are:

  • CVE-2024-38473 — an issue in mod_proxy that allows circumvention of authentication to backend services through improper URL encoding.
  • CVE-2024-38476 — if a vulnerable application is used as a backend, it can lead to local script execution or information leakage.
  • CVE-2024-38474, CVE-2024-38475 — improper output escaping in mod_rewrite allows an attacker to reflect a URL to a directory in the local file system that is processed by the HTTP server but is not accessible via a link.
  • CVE-2024-38472 — the possibility of conducting an SSRF attack against serverləri üçün mükəmməl seçim edir. the Windows platform.
  • CVE-2024-39573 — the possibility of conducting an SSRF (Server-side request forgery) attack on mod_rewrite, allowing processing of URLs in mod_proxy using insecure rules present in the settings (RewriteRule).
  • CVE-2024-36387 — denial of service due to null pointer dereference when using WebSocket over HTTP/2.
  • CVE-2024-38477 — denial of service when processing a specially crafted request in mod_proxy, caused by null pointer dereference.

Təhlükəsizlik ilə əlaqəli olmayan dəyişikliklər arasında:

  • Support for specifying the zone and scope of local IPv6 addresses has been added to the Listen and VirtualHost directives.
  • The contents of the mime.types file have been updated.
  • Optional support for passing file descriptors has been added in mod_cgid.
  • In the mod_tls module, the rustls-ffi package has been updated to version 0.13.0.
  • In the mod_md module, used for automating the retrieval and maintenance of certificates using the ACME (Automatic Certificate Management Environment) protocol, a new directive MDCheckInterval has been introduced to define the certificate revocation check interval.

Mənbə: opennet.ru

DDoS qoruması olan saytlara etibarlı hosting satın alın, VPS VDS serverlər 🔥 DDoS qoruması olan saytlara etibarlı hosting satın alın, VPS VDS serverlər | ProHoster