Release of the Apache HTTP Server 2.4.48
The release of the Apache HTTP Server 2.4.48 has been published (release 2.4.47 was skipped), which includes 39 changes and fixes 8 vulnerabilities: CVE-2021-30641 — incorrect triggering of the section in 'MergeSlashes OFF' mode; CVE-2020-35452 — stack overflow by one null byte in mod_auth_digest; CVE-2021-31618, CVE-2020-26691, CVE-2020-26690, CVE-2020-13950 — dereferencing of NULL pointers in mod_http2, mod_session, and mod_proxy_http; CVE-2020-13938 — the possibility of crashing […]
