RHSA-2017:2882: Moderate: httpd security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): A use-after-free flaw was found in the way httpd handled invalid and previously unregistered HTTP methods specified in the Limit directive used in an .htaccess file. A remote attacker could possibly use this flaw to disclose portions of the server memory, or cause httpd child process to crash. (CVE-2017-9798) Red Hat would like to thank Hanno Böck for reporting this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:2882?
The severity of RHSA-2017:2882 is classified as moderate.
How do I fix RHSA-2017:2882?
To fix RHSA-2017:2882, upgrade the httpd package to version 2.4.6-67.el7_4.5 or higher.
What types of systems are affected by RHSA-2017:2882?
RHSA-2017:2882 affects systems running specific versions of Apache HTTP Server, including various architectures like x86_64 and ppc64le.
What vulnerability is addressed in RHSA-2017:2882?
RHSA-2017:2882 addresses a use-after-free flaw in the way httpd handles invalid HTTP methods.
Is there a specific package version I need for RHSA-2017:2882?
Yes, you need to ensure you are running httpd version 2.4.6-67.el7_4.5 or higher to mitigate the vulnerability.