Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.
Security Fix(es):
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58. (CVE-2023-38709)
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.
Users are recommended to upgrade to version 2.4.59, which fixes this issue.(CVE-2024-24795)
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.(CVE-2024-27316)
{ "severity": "High" }
{ "src": [ "httpd-2.4.43-24.oe1.src.rpm" ], "noarch": [ "httpd-filesystem-2.4.43-24.oe1.noarch.rpm", "httpd-help-2.4.43-24.oe1.noarch.rpm" ], "x86_64": [ "mod_proxy_html-2.4.43-24.oe1.x86_64.rpm", "mod_ssl-2.4.43-24.oe1.x86_64.rpm", "httpd-tools-2.4.43-24.oe1.x86_64.rpm", "mod_session-2.4.43-24.oe1.x86_64.rpm", "mod_ldap-2.4.43-24.oe1.x86_64.rpm", "mod_md-2.4.43-24.oe1.x86_64.rpm", "httpd-2.4.43-24.oe1.x86_64.rpm", "httpd-debuginfo-2.4.43-24.oe1.x86_64.rpm", "httpd-devel-2.4.43-24.oe1.x86_64.rpm", "httpd-debugsource-2.4.43-24.oe1.x86_64.rpm" ], "aarch64": [ "mod_session-2.4.43-24.oe1.aarch64.rpm", "mod_md-2.4.43-24.oe1.aarch64.rpm", "httpd-devel-2.4.43-24.oe1.aarch64.rpm", "mod_ssl-2.4.43-24.oe1.aarch64.rpm", "httpd-debuginfo-2.4.43-24.oe1.aarch64.rpm", "mod_proxy_html-2.4.43-24.oe1.aarch64.rpm", "httpd-debugsource-2.4.43-24.oe1.aarch64.rpm", "httpd-2.4.43-24.oe1.aarch64.rpm", "httpd-tools-2.4.43-24.oe1.aarch64.rpm", "mod_ldap-2.4.43-24.oe1.aarch64.rpm" ] }
{ "src": [ "httpd-2.4.43-24.oe2003sp4.src.rpm" ], "noarch": [ "httpd-filesystem-2.4.43-24.oe2003sp4.noarch.rpm", "httpd-help-2.4.43-24.oe2003sp4.noarch.rpm" ], "x86_64": [ "mod_proxy_html-2.4.43-24.oe2003sp4.x86_64.rpm", "mod_ldap-2.4.43-24.oe2003sp4.x86_64.rpm", "httpd-debuginfo-2.4.43-24.oe2003sp4.x86_64.rpm", "mod_ssl-2.4.43-24.oe2003sp4.x86_64.rpm", "mod_session-2.4.43-24.oe2003sp4.x86_64.rpm", "httpd-debugsource-2.4.43-24.oe2003sp4.x86_64.rpm", "httpd-devel-2.4.43-24.oe2003sp4.x86_64.rpm", "httpd-tools-2.4.43-24.oe2003sp4.x86_64.rpm", "httpd-2.4.43-24.oe2003sp4.x86_64.rpm", "mod_md-2.4.43-24.oe2003sp4.x86_64.rpm" ], "aarch64": [ "mod_md-2.4.43-24.oe2003sp4.aarch64.rpm", "httpd-debugsource-2.4.43-24.oe2003sp4.aarch64.rpm", "mod_ssl-2.4.43-24.oe2003sp4.aarch64.rpm", "mod_ldap-2.4.43-24.oe2003sp4.aarch64.rpm", "httpd-devel-2.4.43-24.oe2003sp4.aarch64.rpm", "httpd-tools-2.4.43-24.oe2003sp4.aarch64.rpm", "httpd-debuginfo-2.4.43-24.oe2003sp4.aarch64.rpm", "mod_proxy_html-2.4.43-24.oe2003sp4.aarch64.rpm", "mod_session-2.4.43-24.oe2003sp4.aarch64.rpm", "httpd-2.4.43-24.oe2003sp4.aarch64.rpm" ] }
{ "src": [ "httpd-2.4.51-21.oe2203.src.rpm", "httpd-2.4.51-21.oe2203sp1.src.rpm", "httpd-2.4.51-21.oe2203sp2.src.rpm", "httpd-2.4.51-21.oe2203sp3.src.rpm" ], "noarch": [ "httpd-filesystem-2.4.51-21.oe2203.noarch.rpm", "httpd-help-2.4.51-21.oe2203.noarch.rpm", "httpd-filesystem-2.4.51-21.oe2203sp1.noarch.rpm", "httpd-help-2.4.51-21.oe2203sp1.noarch.rpm", "httpd-help-2.4.51-21.oe2203sp2.noarch.rpm", "httpd-filesystem-2.4.51-21.oe2203sp2.noarch.rpm", "httpd-help-2.4.51-21.oe2203sp3.noarch.rpm", "httpd-filesystem-2.4.51-21.oe2203sp3.noarch.rpm" ], "x86_64": [ "httpd-tools-2.4.51-21.oe2203.x86_64.rpm", "httpd-devel-2.4.51-21.oe2203.x86_64.rpm", "httpd-2.4.51-21.oe2203.x86_64.rpm", "mod_md-2.4.51-21.oe2203.x86_64.rpm", "mod_session-2.4.51-21.oe2203.x86_64.rpm", "mod_ssl-2.4.51-21.oe2203.x86_64.rpm", "mod_ldap-2.4.51-21.oe2203.x86_64.rpm", "httpd-debugsource-2.4.51-21.oe2203.x86_64.rpm", "mod_proxy_html-2.4.51-21.oe2203.x86_64.rpm", "httpd-debuginfo-2.4.51-21.oe2203.x86_64.rpm", "httpd-tools-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_ssl-2.4.51-21.oe2203sp1.x86_64.rpm", "httpd-devel-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_session-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_ldap-2.4.51-21.oe2203sp1.x86_64.rpm", "httpd-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp1.x86_64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_md-2.4.51-21.oe2203sp1.x86_64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_ldap-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp2.x86_64.rpm", "mod_md-2.4.51-21.oe2203sp2.x86_64.rpm", "mod_ssl-2.4.51-21.oe2203sp2.x86_64.rpm", "mod_session-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-tools-2.4.51-21.oe2203sp2.x86_64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-devel-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-tools-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_session-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_ssl-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_ldap-2.4.51-21.oe2203sp3.x86_64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp3.x86_64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_md-2.4.51-21.oe2203sp3.x86_64.rpm", "httpd-2.4.51-21.oe2203sp3.x86_64.rpm", "httpd-devel-2.4.51-21.oe2203sp3.x86_64.rpm" ], "aarch64": [ "httpd-debuginfo-2.4.51-21.oe2203.aarch64.rpm", "mod_session-2.4.51-21.oe2203.aarch64.rpm", "mod_md-2.4.51-21.oe2203.aarch64.rpm", "mod_ssl-2.4.51-21.oe2203.aarch64.rpm", "httpd-debugsource-2.4.51-21.oe2203.aarch64.rpm", "mod_ldap-2.4.51-21.oe2203.aarch64.rpm", "httpd-2.4.51-21.oe2203.aarch64.rpm", "mod_proxy_html-2.4.51-21.oe2203.aarch64.rpm", "httpd-devel-2.4.51-21.oe2203.aarch64.rpm", "httpd-tools-2.4.51-21.oe2203.aarch64.rpm", "mod_ssl-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp1.aarch64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp1.aarch64.rpm", "mod_session-2.4.51-21.oe2203sp1.aarch64.rpm", "mod_ldap-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-devel-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-tools-2.4.51-21.oe2203sp1.aarch64.rpm", "mod_md-2.4.51-21.oe2203sp1.aarch64.rpm", "mod_md-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp2.aarch64.rpm", "mod_ldap-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-2.4.51-21.oe2203sp2.aarch64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp2.aarch64.rpm", "mod_session-2.4.51-21.oe2203sp2.aarch64.rpm", "mod_ssl-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-tools-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-devel-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-devel-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_md-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_session-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_ssl-2.4.51-21.oe2203sp3.aarch64.rpm", "httpd-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp3.aarch64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp3.aarch64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp3.aarch64.rpm", "httpd-tools-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_ldap-2.4.51-21.oe2203sp3.aarch64.rpm" ] }
{ "src": [ "httpd-2.4.51-21.oe2203sp1.src.rpm" ], "noarch": [ "httpd-filesystem-2.4.51-21.oe2203sp1.noarch.rpm", "httpd-help-2.4.51-21.oe2203sp1.noarch.rpm" ], "x86_64": [ "httpd-tools-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_ssl-2.4.51-21.oe2203sp1.x86_64.rpm", "httpd-devel-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_session-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_ldap-2.4.51-21.oe2203sp1.x86_64.rpm", "httpd-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp1.x86_64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp1.x86_64.rpm", "mod_md-2.4.51-21.oe2203sp1.x86_64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp1.x86_64.rpm" ], "aarch64": [ "mod_ssl-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp1.aarch64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp1.aarch64.rpm", "mod_session-2.4.51-21.oe2203sp1.aarch64.rpm", "mod_ldap-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-devel-2.4.51-21.oe2203sp1.aarch64.rpm", "httpd-tools-2.4.51-21.oe2203sp1.aarch64.rpm", "mod_md-2.4.51-21.oe2203sp1.aarch64.rpm" ] }
{ "src": [ "httpd-2.4.51-21.oe2203sp2.src.rpm" ], "noarch": [ "httpd-help-2.4.51-21.oe2203sp2.noarch.rpm", "httpd-filesystem-2.4.51-21.oe2203sp2.noarch.rpm" ], "x86_64": [ "mod_ldap-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp2.x86_64.rpm", "mod_md-2.4.51-21.oe2203sp2.x86_64.rpm", "mod_ssl-2.4.51-21.oe2203sp2.x86_64.rpm", "mod_session-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-tools-2.4.51-21.oe2203sp2.x86_64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp2.x86_64.rpm", "httpd-devel-2.4.51-21.oe2203sp2.x86_64.rpm" ], "aarch64": [ "mod_md-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp2.aarch64.rpm", "mod_ldap-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-2.4.51-21.oe2203sp2.aarch64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp2.aarch64.rpm", "mod_session-2.4.51-21.oe2203sp2.aarch64.rpm", "mod_ssl-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-tools-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-devel-2.4.51-21.oe2203sp2.aarch64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp2.aarch64.rpm" ] }
{ "src": [ "httpd-2.4.51-21.oe2203sp3.src.rpm" ], "noarch": [ "httpd-help-2.4.51-21.oe2203sp3.noarch.rpm", "httpd-filesystem-2.4.51-21.oe2203sp3.noarch.rpm" ], "x86_64": [ "httpd-tools-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_session-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_ssl-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_ldap-2.4.51-21.oe2203sp3.x86_64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp3.x86_64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp3.x86_64.rpm", "mod_md-2.4.51-21.oe2203sp3.x86_64.rpm", "httpd-2.4.51-21.oe2203sp3.x86_64.rpm", "httpd-devel-2.4.51-21.oe2203sp3.x86_64.rpm" ], "aarch64": [ "httpd-devel-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_md-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_session-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_ssl-2.4.51-21.oe2203sp3.aarch64.rpm", "httpd-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_proxy_html-2.4.51-21.oe2203sp3.aarch64.rpm", "httpd-debuginfo-2.4.51-21.oe2203sp3.aarch64.rpm", "httpd-debugsource-2.4.51-21.oe2203sp3.aarch64.rpm", "httpd-tools-2.4.51-21.oe2203sp3.aarch64.rpm", "mod_ldap-2.4.51-21.oe2203sp3.aarch64.rpm" ] }