Chapter 3. Security Fixes


This update includes the following security fixes:

IDImpactSummary

CVE-2021-41773

Important

httpd: path traversal and file disclosure vulnerability [jbcs-httpd-2.4]

CVE-2021-40438

Important

httpd: mod_proxy: SSRF via a crafted request uri-path containing "unix:" [jbcs-httpd-2.4]

CVE-2021-3712

Moderate

openssl: Read buffer overruns processing ASN.1 strings [jbcs-httpd-2.4]

CVE-2021-3688

Moderate

mod_proxy: Red Hat JBCS: URL normalization issue with dot-dot-semicolon(s) leads to information disclosure [jbcs-httpd-2.4]

CVE-2021-22924

Moderate

curl: Bad connection reuse due to flawed path name checks [jbcs-httpd-2.4]

CVE-2021-22922

Moderate

curl: Content not matching hash in Metalink is not being discarded [jbcs-httpd-2.4]

CVE-2021-22923

Moderate

curl: Metalink download sends credentials [jbcs-httpd-2.4]

CVE-2021-30641

Moderate

httpd: Unexpected URL matching with 'MergeSlashes OFF' [jbcs-httpd-2.4]

CVE-2019-17567

Moderate

httpd: mod_proxy_wstunnel tunneling of non Upgraded connection [jbcs-httpd-2.4]

CVE-2021-26691

Moderate

httpd: mod_session: Heap overflow via a crafted SessionHeader value [jbcs-httpd-2.4]

CVE-2021-26690

Moderate

httpd: mod_session: NULL pointer dereference when parsing Cookie header [jbcs-httpd-2.4]

CVE-2021-23840

Moderate

openssl: integer overflow in CipherUpdate [jbcs-httpd-2.4]

CVE-2021-23841

Moderate

openssl: NULL pointer dereference in X509_issuer_and_serial_hash() [jbcs-httpd-2.4]

CVE-2020-14155

Low

pcre: Integer overflow when parsing callout numeric arguments [jbcs-httpd-2.4]

CVE-2019-20838

Low

pcre: Buffer over-read in JIT when UTF is disabled and \X or \R has fixed quantifier greater than 1 [jbcs-httpd-2.4]

CVE-2021-22925

Low

curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure [jbcs-httpd-2.4]

CVE-2020-13950

Low

httpd: mod_proxy NULL pointer dereference [jbcs-httpd-2.4]

CVE-2020-35452

Low

httpd: Single zero byte stack overflow in mod_auth_digest [jbcs-httpd-2.4]

Red Hat logoGithubRedditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

© 2024 Red Hat, Inc.