第 3 章 安全修复
这个版本包括以下安全修复:
| ID | 影响 | 概述 |
|---|---|---|
| 重要的 | httpd: path traversal and file disclosure vulnerability [jbcs-httpd-2.4] | |
| 重要的 | httpd: mod_proxy: SSRF via a crafted request uri-path containing "unix:" [jbcs-httpd-2.4] | |
| Moderate(中度) | openssl: Read buffer overruns processing ASN.1 字符串 [jbcs-httpd-2.4] | |
| Moderate(中度) | mod_proxy:Red Hat JBCS: URL 规范化问题带有点-dot-semicolon (s)会导致信息披露 [jbcs-httpd-2.4] | |
| Moderate(中度) | curl:由于有缺陷的路径名检查 [jbcs-httpd-2.4] | |
| Moderate(中度) | curl:在 Metalink 中,内容不匹配的哈希值不会被丢弃 [jbcs-httpd-2.4] | |
| Moderate(中度) | curl: Metalink download 发送凭证 [jbcs-httpd-2.4] | |
| Moderate(中度) | httpd: Unexpected URL 与 'MergeSlashes OFF' [jbcs-httpd-2.4] 匹配 | |
| Moderate(中度) | httpd: mod_proxy_wstunnel tunneling of non Upgraded connection [jbcs-httpd-2.4] | |
| Moderate(中度) | httpd: mod_session: Heap overflow via a crafted SessionHeader value [jbcs-httpd-2.4] | |
| Moderate(中度) | httpd: mod_session: NULL pointer dereference when parsing Cookie header [jbcs-httpd-2.4] | |
| Moderate(中度) | openssl: integer overflow in CipherUpdate [jbcs-httpd-2.4] | |
| Moderate(中度) | openssl: NULL pointer dereference in X509_issuer_and_serial_hash() [jbcs-httpd-2.4] | |
| 低 | pcre:解析 callout 数字参数 [jbcs-httpd-2.4] | |
| 低 | pcre:当 UTF 被禁用并且 \X 或 \R 的固定限定符大于 1 [jbcs-httpd-2.4] | |
| 低 | curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure [jbcs-httpd-2.4] | |
| 低 | httpd: mod_proxy NULL pointer dereference [jbcs-httpd-2.4] | |
| 低 | httpd: Single zero byte stack overflow in mod_auth_digest [jbcs-httpd-2.4] |