Red Hat Security Advisory: httpd security, bug fix, and enhancement update
🔗 CVE IDs covered (6)
📋 Description
CVE-2017-15715 — httpd: bypass with a trailing newline in the file name CVE-2018-1283 — httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications CVE-2018-1303 — httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS CVE-2019-10098 — httpd: mod_rewrite potential open redirect CVE-2020-1927 — httpd: mod_rewrite configurations vulnerable to open redirect CVE-2020-1934 — httpd: mod_proxy_ftp use of uninitialized value
🎯 Affected products75
- Red Hat Enterprise Linux Client Optional (v. 7)
- Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- Red Hat Enterprise Linux Server (v. 7)
- Red Hat Enterprise Linux Server Optional (v. 7)
- Red Hat Enterprise Linux Workstation (v. 7)
- Red Hat Enterprise Linux Workstation Optional (v. 7)
- httpd-0:2.4.6-95.el7.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7)
- httpd-0:2.4.6-95.el7.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7)
- httpd-0:2.4.6-95.el7.s390x as a component of Red Hat Enterprise Linux Server (v. 7)
- httpd-0:2.4.6-95.el7.src as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- httpd-0:2.4.6-95.el7.src as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- httpd-0:2.4.6-95.el7.src as a component of Red Hat Enterprise Linux Server (v. 7)
- httpd-0:2.4.6-95.el7.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
- httpd-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- httpd-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- httpd-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7)
- httpd-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.ppc64 as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.ppc64le as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.s390x as a component of Red Hat Enterprise Linux Server (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.s390x as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation (v. 7)
- httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
- httpd-devel-0:2.4.6-95.el7.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7)
- +45 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Workaround: This flaw requires the use of certain Rewrite configuration directives. The following command can be used to search for possible vulnerable configurations: grep -R '^\s*Rewrite' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_rewrite.html
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2020:3958
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.9_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1560395
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1560399
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1560614
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1715981
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1724879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1743959
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820772
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3958.json