RHSA-2020:3958MediumCVSS 6.1

Red Hat Security Advisory: httpd security, bug fix, and enhancement update

Published
September 29, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2017-15715 — httpd: bypass with a trailing newline in the file name CVE-2018-1283 — httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications CVE-2018-1303 — httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS CVE-2019-10098 — httpd: mod_rewrite potential open redirect CVE-2020-1927 — httpd: mod_rewrite configurations vulnerable to open redirect CVE-2020-1934 — httpd: mod_proxy_ftp use of uninitialized value

🎯 Affected products75

  • Red Hat Enterprise Linux Client Optional (v. 7)
  • Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • Red Hat Enterprise Linux Server (v. 7)
  • Red Hat Enterprise Linux Server Optional (v. 7)
  • Red Hat Enterprise Linux Workstation (v. 7)
  • Red Hat Enterprise Linux Workstation Optional (v. 7)
  • httpd-0:2.4.6-95.el7.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7)
  • httpd-0:2.4.6-95.el7.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7)
  • httpd-0:2.4.6-95.el7.s390x as a component of Red Hat Enterprise Linux Server (v. 7)
  • httpd-0:2.4.6-95.el7.src as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • httpd-0:2.4.6-95.el7.src as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • httpd-0:2.4.6-95.el7.src as a component of Red Hat Enterprise Linux Server (v. 7)
  • httpd-0:2.4.6-95.el7.src as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • httpd-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • httpd-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • httpd-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7)
  • httpd-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.ppc64 as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.ppc64le as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.s390x as a component of Red Hat Enterprise Linux Server (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.s390x as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Client Optional (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Server Optional (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation (v. 7)
  • httpd-debuginfo-0:2.4.6-95.el7.x86_64 as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
  • httpd-devel-0:2.4.6-95.el7.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7)
  • +45 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the updated packages, the httpd daemon will be restarted automatically. Workaround: This flaw requires the use of certain Rewrite configuration directives. The following command can be used to search for possible vulnerable configurations: grep -R '^\s*Rewrite' /etc/httpd/ See https://httpd.apache.org/docs/2.4/mod/mod_rewrite.html

🔗 References (12)