[CLSA-2022:1648136177] Fixed CVEs in httpd: CVE-2022-22720, CVE-2022-22721
Type:
security
Severity:
Critical
Release date:
2022-03-24
Description:
- CVE-2022-22720: simpler connection close logic if discarding the request body fails - CVE-2022-22721: make sure and check that LimitXMLRequestBody fits in system memory
Updated packages:
  • httpd-devel-2.2.15-72.el6.tuxcare.els4.i686.rpm
    sha:dbab50dca1af5309e76bdec0bf000dc0e77b54a7
  • mod_ssl-2.2.15-72.el6.tuxcare.els4.x86_64.rpm
    sha:675b03a7fb6dc9217a0a773d87c407d705ce60c6
  • httpd-devel-2.2.15-72.el6.tuxcare.els4.x86_64.rpm
    sha:77fb4f6a02e581a2bbb472a6e6b43fda0a7d6bcc
  • httpd-tools-2.2.15-72.el6.tuxcare.els4.x86_64.rpm
    sha:e1fae3b5106171f354c4965c45f8d051e6ba1170
  • httpd-manual-2.2.15-72.el6.tuxcare.els4.noarch.rpm
    sha:b85e40564b7fd2a9d18654b7df42c22091c784da
  • httpd-2.2.15-72.el6.tuxcare.els4.x86_64.rpm
    sha:3be2130e9fc791e05a8318bb218e1665c52ea925
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.