Release of Apache HTTP Server 2.4.61 addressing vulnerabilities

The release of Apache HTTP Server 2.4.61 is now available, published shortly after version 2.4.60, and includes a fix for a regression issue that caused a vulnerability (CVE-2024-39884) allowing the viewing of script code processed through the AddType directive (for example, it is possible to craft a specially formatted request to a PHP script that will display its content instead of executing it).

Version 2.4.60 of Apache httpd addressed 8 vulnerabilities, of which 5 are marked as critical, and introduced 13 changes. Identified vulnerabilities:

  • CVE-2024-38473 — an issue in mod_proxy that allows bypassing authentication to backend services through the use of incorrect encoding in the URL.
  • CVE-2024-38476 — if there is a vulnerable application used as a backend, it may lead to the execution of local scripts or information leakage.
  • CVE-2024-38474, CVE-2024-38475 — improper escaping of output in mod_rewrite allows an attacker to reflect a URL on a directory in the local filesystem that is processed by the HTTP server but is not accessible via a link.
  • CVE-2024-38472 — the possibility of performing an SSRF attack against servers the Windows platform.
  • CVE-2024-39573 — the possibility to carry out an SSRF (Server-side request forgery) attack on mod_rewrite, allowing the processing of a URL in mod_proxy using unsafe rules present in the configurations (RewriteRule).
  • CVE-2024-36387 — denial of service caused by dereferencing a null pointer when using the WebSocket protocol over HTTP/2.
  • CVE-2024-38477 — denial of service when processing a specially crafted request in mod_proxy, caused by dereferencing a null pointer.

Among the non-security-related changes:

  • Support for specifying the scope and area of local IPv6 addresses has been added to the Listen and VirtualHost directives.
  • The content of the mime.types file has been updated.
  • Optional support for passing file descriptors has been added in mod_cgid.
  • The mod_tls module has been updated with the rustls-ffi package to version 0.13.0.
  • In the mod_md module, used for automating the retrieval and management of certificates using the ACME (Automatic Certificate Management Environment) protocol, the MDCheckInterval directive has been introduced to define the interval for checking certificate revocation.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster