{"id":91158,"date":"2020-08-09T01:43:01","date_gmt":"2020-08-08T23:43:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-http-servera-apache-2-4-46-s-ustraneniem-uyazvimostej"},"modified":"2020-08-09T01:43:01","modified_gmt":"2020-08-08T23:43:01","slug":"reliz-http-servera-apache-2-4-46-s-ustraneniem-uyazvimostej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/reliz-http-servera-apache-2-4-46-s-ustraneniem-uyazvimostej","title":{"rendered":"Liberaci\u00f3n del servidor HTTP Apache 2.4.46 con correcciones de seguridad","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.mail-archive.com\/announce@httpd.apache.org\/msg00146.html\">Publicado<\/a><\/noindex> liberaci\u00f3n del servidor HTTP Apache 2.4.46 (se omitieron las versiones 2.4.44 y 2.4.45), que presenta <noindex><a rel=\"nofollow\" href=\"http:\/\/www.apache.org\/dist\/httpd\/CHANGES_2.4.46\">17 cambios<\/a><\/noindex> y se han corregido <noindex><a rel=\"nofollow\" href=\"http:\/\/httpd.apache.org\/security\/vulnerabilities_24.html\">3 vulnerabilidades<\/a><\/noindex>:<\/p>\n<ul>\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mail-archive.com\/announce@httpd.apache.org\/msg00147.html\">CVE-2020-11984<\/a><\/noindex> \u2014 desbordamiento de b\u00fafer en el m\u00f3dulo mod_proxy_uwsgi, lo que puede provocar una fuga de informaci\u00f3n o la ejecuci\u00f3n de c\u00f3digo en el servidor al enviar una solicitud especialmente formateada. La explotaci\u00f3n de la vulnerabilidad se realiza mediante el env\u00edo de un encabezado HTTP muy largo. Para protegerse, se ha a\u00f1adido un bloqueo de encabezados que superen los 16K (l\u00edmite definido en la especificaci\u00f3n del protocolo).\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mail-archive.com\/announce@httpd.apache.org\/msg00149.html\">CVE-2020-11993<\/a><\/noindex> \u2014 vulnerabilidad en el m\u00f3dulo mod_http2 que permite provocar un fallo en el proceso al enviar una solicitud con un encabezado HTTP\/2 especialmente formateado. El problema se presenta al activar la depuraci\u00f3n o el rastreo en el m\u00f3dulo mod_http2 y se manifiesta en la corrupci\u00f3n del contenido de la memoria debido a una condici\u00f3n de carrera al guardar informaci\u00f3n en el registro. El problema no se presenta al establecer LogLevel en \"info\".\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mail-archive.com\/announce@httpd.apache.org\/msg00150.html\">CVE-2020-9490<\/a><\/noindex> \u2014 vulnerabilidad en el m\u00f3dulo mod_http2 que permite provocar un fallo en el proceso al enviar una solicitud a trav\u00e9s de HTTP\/2 con un valor de encabezado especialmente formateado 'Cache-Digest' (el fallo ocurre al intentar realizar una operaci\u00f3n HTTP\/2 PUSH para el recurso). Para bloquear la vulnerabilidad, se puede utilizar la configuraci\u00f3n 'H2Push off'.\n<li class=\"l\"> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mail-archive.com\/announce@httpd.apache.org\/msg00148.html\">CVE-2020-11985<\/a><\/noindex> \u2014 vulnerabilidad mod_remoteip que permite organizar el suplantado de direcciones IP al hacer proxy, utilizando mod_remoteip y mod_rewrite. El problema se manifiesta solo en versiones de 2.4.1 a 2.4.23.\n<\/ul>\n<p>Los cambios m\u00e1s destacados no relacionados con la seguridad: <\/p>\n<ul>\n<li class=\"l\"> Se elimin\u00f3 el soporte para la especificaci\u00f3n preliminar de mod_http2 <noindex><a rel=\"nofollow\" href=\"https:\/\/datatracker.ietf.org\/doc\/draft-kazuho-h2-cache-digest\/\">kazuho-h2-cache-digest<\/a><\/noindex>, cuyo desarrollo se ha detenido.\n<li class=\"l\"> Se ha cambiado el comportamiento de la directiva 'LimitRequestFields' en mod_http2, establecer el valor 0 ahora desactiva la limitaci\u00f3n.\n<li class=\"l\"> En mod_http2 se ha garantizado el manejo de conexiones primarias y secundarias (master\/secondary) y la marcaci\u00f3n de m\u00e9todos seg\u00fan su uso.\n<li class=\"l\"> En caso de recibir contenido de cabecera Last-Modified incorrecto de un script FCGI\/CGI, esta cabecera ahora se elimina en lugar de ser reemplazada por la \u00e9poca (Unix epoch).\n<li class=\"l\"> Se agreg\u00f3 una funci\u00f3n ap_parse_strict_length() al c\u00f3digo para el an\u00e1lisis estricto del tama\u00f1o del contenido.\n<li class=\"l\"> En mod_proxy_fcgi, en ProxyFCGISetEnvIf, se ha garantizado la eliminaci\u00f3n de variables de entorno si la expresi\u00f3n especificada devuelve False.\n<li class=\"l\"> Se ha corregido una condici\u00f3n de carrera y un posible fallo de mod_ssl al usar un certificado de cliente configurado a trav\u00e9s de SSLProxyMachineCertificateFile.\n<li class=\"l\"> Se ha solucionado una fuga de memoria en mod_ssl.\n<li class=\"l\"> En mod_proxy_http2 se ha garantizado el uso del par\u00e1metro proxy '<noindex><a rel=\"nofollow\" href=\"https:\/\/httpd.apache.org\/docs\/2.4\/mod\/mod_proxy.html\">ping<\/a><\/noindex>\u2018 al verificar la operatividad de una nueva conexi\u00f3n o de una reutilizada con el backend.\n<li class=\"l\"> Se ha detenido la vinculaci\u00f3n de httpd con la opci\u00f3n '-lsystemd', si se activa mod_systemd.\n<li class=\"l\"> En mod_proxy_http2 se ha tomado en cuenta la configuraci\u00f3n ProxyTimeout al esperar datos entrantes a trav\u00e9s de conexiones con el backend.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53517\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.46 (\u0432\u044b\u043f\u0443\u0441\u043a\u0438 2.4.44 \u0438 2.4.45 \u0431\u044b\u043b\u0438 \u043f\u0440\u043e\u043f\u0443\u0449\u0435\u043d\u044b), \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043e 17 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0439 \u0438 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043e 3 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438: CVE-2020-11984 &#8212; \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 \u043c\u043e\u0434\u0443\u043b\u0435 mod_proxy_uwsgi, \u043a\u043e\u0442\u043e\u0440\u043e\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 \u043a\u043e\u0434\u0430 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0435 \u043f\u0440\u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u0430. \u042d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043e\u0441\u0443\u0449\u0435\u0441\u0442\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0447\u0435\u0440\u0435\u0437 \u043f\u0435\u0440\u0435\u0434\u0430\u0447\u0443 \u043e\u0447\u0435\u043d\u044c \u0434\u043b\u0438\u043d\u043d\u043e\u0433\u043e HTTP-\u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043a\u0430. \u0414\u043b\u044f \u0437\u0430\u0449\u0438\u0442\u044b \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0430 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-91158","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.46 (\u0432\u044b\u043f\u0443\u0441\u043a\u0438 2.4.44 \u0438 2.4.45 \u0431\u044b\u043b\u0438 \u043f\u0440\u043e\u043f\u0443\u0449\u0435\u043d\u044b), \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/reliz-http-servera-apache-2-4-46-s-ustraneniem-uyazvimostej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.46 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.46 (\u0432\u044b\u043f\u0443\u0441\u043a\u0438 2.4.44 \u0438 2.4.45 \u0431\u044b\u043b\u0438 \u043f\u0440\u043e\u043f\u0443\u0449\u0435\u043d\u044b), \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/reliz-http-servera-apache-2-4-46-s-ustraneniem-uyazvimostej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-08-08T23:43:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-08-08T23:43:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Lanzamiento del servidor http Apache 2.4.46 con correcci\u00f3n de vulnerabilidades | ProHoster","description":"Se ha publicado la versi\u00f3n del servidor HTTP Apache 2.4.46 (se omitieron las versiones 2.4.44 y 2.4.45), en la cual.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/reliz-http-servera-apache-2-4-46-s-ustraneniem-uyazvimostej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 http-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.46 \u0441 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 HTTP-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 Apache 2.4.46 (\u0432\u044b\u043f\u0443\u0441\u043a\u0438 2.4.44 \u0438 2.4.45 \u0431\u044b\u043b\u0438 \u043f\u0440\u043e\u043f\u0443\u0449\u0435\u043d\u044b), \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/reliz-http-servera-apache-2-4-46-s-ustraneniem-uyazvimostej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-08-08T23:43:01+00:00","article:modified_time":"2020-08-08T23:43:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"91158","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 12:33:24","updated":"2022-09-28 03:36:52","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/91158","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=91158"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/91158\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=91158"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=91158"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=91158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}