RHSA-2025:3453HighCVSS 8.1
Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-52425 — expat: parsing large tokens can trigger a denial of service CVE-2024-5535 — openssl: SSL_select_next_proto buffer overread CVE-2024-24795 — httpd: HTTP Response Splitting in multiple modules CVE-2024-36387 — mod_http2: DoS by null pointer in websocket over HTTP/2 CVE-2024-45490 — libexpat: Negative Length Parsing Vulnerability in libexpat CVE-2024-56171 — libxml2: Use-After-Free in libxml2 CVE-2025-24928 — libxml2: Stack-based buffer overflow in xmlSnprintfElements of libxml2
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2025:3453
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_core_services/2.4.62/html/red_hat_jboss_core_services_apache_http_server_2.4.62_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262877
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2294581
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2295006
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2308615
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346416
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346421
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3453.json