RHSA-2022:0288: Important: httpd:2.4 security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: modlua: Possible buffer overflow when parsing multipart content (CVE-2021-44790) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.37-16.module+el8.1.0+13809+822d170a.3 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.37-16.module+el8.1.0+13809+822d170a.3 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.37-16.module+el8.1.0+13809+822d170a.3 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-16.module+el8.1.0+13809+822d170a.3 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.37-16.module+el8.1.0+13809+822d170a.3 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.37-16.module+el8.1.0+13809+822d170a.3 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.37-16.module+el8.1.0+13809+822d170a.3 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.37-16.module+el8.1.0+13809+822d170a.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in httpd-2.4.37-16.module+el8.1.0+13809+822d170a.3.x86_64.rpm - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in mod_http2-1.11.3-3.module+el8.1.0+7763+babdfe5b.1.x86_64.rpm - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in mod_ldap-2.4.37-16.module+el8.1.0+13809+822d170a.3.x86_64.rpm - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in mod_md-2.4.37-16.module+el8.1.0+13809+822d170a.3.x86_64.rpm - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in mod_proxy_html-2.4.37-16.module+el8.1.0+13809+822d170a.3.x86_64.rpm - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in mod_session-2.4.37-16.module+el8.1.0+13809+822d170a.3.x86_64.rpm - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in mod_ssl-2.4.37-16.module+el8.1.0+13809+822d170a.3.x86_64.rpm
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:0288?
The severity of RHSA-2022:0288 is classified as important.
How do I fix RHSA-2022:0288?
To fix RHSA-2022:0288, you should update the httpd package to version 2.4.37-16.module+el8.1.0+13809+822d170a.3.
What vulnerability is addressed by RHSA-2022:0288?
RHSA-2022:0288 addresses a buffer overflow vulnerability in mod_lua while parsing multipart content (CVE-2021-44790).
Which packages are affected by RHSA-2022:0288?
The affected packages include httpd, httpd-debuginfo, httpd-devel, and httpd-tools among others.
What can happen if RHSA-2022:0288 is not addressed?
If RHSA-2022:0288 is not addressed, attackers may exploit the buffer overflow vulnerability, potentially leading to security breaches.