[CLSA-2025:1758102473] httpd: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2025-09-17 09:47:57 UTC
Description:
- CVE-2024-47252: escape special characters in user-supplied data for mod_ssl logging - CVE-2025-49812: remove support for TLS upgrade to fix HTTP desynchronisation attack vulnerability
Updated packages:
  • httpd-2.4.6-99.el7.1.tuxcare.els9.x86_64.rpm
    sha:105eb22ba80fbeadf8b8009b915b99ce0f651b47fba8935ab9aa4fe16f82092f
  • httpd-devel-2.4.6-99.el7.1.tuxcare.els9.x86_64.rpm
    sha:e2faf6e0012df1a81d2467ff66ee91a6840e75c98e02c473c5c12d67d8094286
  • httpd-manual-2.4.6-99.el7.1.tuxcare.els9.noarch.rpm
    sha:0d915a9edab135447b0bca3203b00f83a2f1670def128cf13be5dbb775eb3ece
  • httpd-tools-2.4.6-99.el7.1.tuxcare.els9.x86_64.rpm
    sha:64d39728aaa7538cb158d77399ff75373b39c7b0e6fffe0879dfd0c2684d690b
  • mod_ldap-2.4.6-99.el7.1.tuxcare.els9.x86_64.rpm
    sha:e51ef3254aa38fd7d3579fff0489cea6c76691166cfeb69637535fe631d63621
  • mod_proxy_html-2.4.6-99.el7.1.tuxcare.els9.x86_64.rpm
    sha:4113063a196d3d2061ecacefd4da937a3c95a411ae9f0e5f12268adf64e8d7dc
  • mod_session-2.4.6-99.el7.1.tuxcare.els9.x86_64.rpm
    sha:98df8fb091e45596d13e49831aff1154acf9eba5027667e6f48028e69f028c51
  • mod_ssl-2.4.6-99.el7.1.tuxcare.els9.x86_64.rpm
    sha:a52128d519894a8d4605c6445a6f9c743e75d830c916457fcf96ed5b7be0a6b8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.