Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.
Security Fix(es):
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users are recommended to upgrade to version 2.4.62, which fixes this issue.
(CVE-2024-40725)
{ "severity": "Medium" }
{ "noarch": [ "httpd-filesystem-2.4.58-7.oe2403.noarch.rpm", "httpd-help-2.4.58-7.oe2403.noarch.rpm" ], "aarch64": [ "httpd-2.4.58-7.oe2403.aarch64.rpm", "httpd-debuginfo-2.4.58-7.oe2403.aarch64.rpm", "httpd-debugsource-2.4.58-7.oe2403.aarch64.rpm", "httpd-devel-2.4.58-7.oe2403.aarch64.rpm", "httpd-tools-2.4.58-7.oe2403.aarch64.rpm", "mod_ldap-2.4.58-7.oe2403.aarch64.rpm", "mod_md-2.4.58-7.oe2403.aarch64.rpm", "mod_proxy_html-2.4.58-7.oe2403.aarch64.rpm", "mod_session-2.4.58-7.oe2403.aarch64.rpm", "mod_ssl-2.4.58-7.oe2403.aarch64.rpm" ], "src": [ "httpd-2.4.58-7.oe2403.src.rpm" ], "x86_64": [ "httpd-2.4.58-7.oe2403.x86_64.rpm", "httpd-debuginfo-2.4.58-7.oe2403.x86_64.rpm", "httpd-debugsource-2.4.58-7.oe2403.x86_64.rpm", "httpd-devel-2.4.58-7.oe2403.x86_64.rpm", "httpd-tools-2.4.58-7.oe2403.x86_64.rpm", "mod_ldap-2.4.58-7.oe2403.x86_64.rpm", "mod_md-2.4.58-7.oe2403.x86_64.rpm", "mod_proxy_html-2.4.58-7.oe2403.x86_64.rpm", "mod_session-2.4.58-7.oe2403.x86_64.rpm", "mod_ssl-2.4.58-7.oe2403.x86_64.rpm" ] }
{ "noarch": [ "httpd-filesystem-2.4.51-23.oe2203sp4.noarch.rpm", "httpd-help-2.4.51-23.oe2203sp4.noarch.rpm" ], "aarch64": [ "httpd-2.4.51-23.oe2203sp4.aarch64.rpm", "httpd-debuginfo-2.4.51-23.oe2203sp4.aarch64.rpm", "httpd-debugsource-2.4.51-23.oe2203sp4.aarch64.rpm", "httpd-devel-2.4.51-23.oe2203sp4.aarch64.rpm", "httpd-tools-2.4.51-23.oe2203sp4.aarch64.rpm", "mod_ldap-2.4.51-23.oe2203sp4.aarch64.rpm", "mod_md-2.4.51-23.oe2203sp4.aarch64.rpm", "mod_proxy_html-2.4.51-23.oe2203sp4.aarch64.rpm", "mod_session-2.4.51-23.oe2203sp4.aarch64.rpm", "mod_ssl-2.4.51-23.oe2203sp4.aarch64.rpm" ], "src": [ "httpd-2.4.51-23.oe2203sp4.src.rpm" ], "x86_64": [ "httpd-2.4.51-23.oe2203sp4.x86_64.rpm", "httpd-debuginfo-2.4.51-23.oe2203sp4.x86_64.rpm", "httpd-debugsource-2.4.51-23.oe2203sp4.x86_64.rpm", "httpd-devel-2.4.51-23.oe2203sp4.x86_64.rpm", "httpd-tools-2.4.51-23.oe2203sp4.x86_64.rpm", "mod_ldap-2.4.51-23.oe2203sp4.x86_64.rpm", "mod_md-2.4.51-23.oe2203sp4.x86_64.rpm", "mod_proxy_html-2.4.51-23.oe2203sp4.x86_64.rpm", "mod_session-2.4.51-23.oe2203sp4.x86_64.rpm", "mod_ssl-2.4.51-23.oe2203sp4.x86_64.rpm" ] }
{ "noarch": [ "httpd-filesystem-2.4.51-23.oe2203sp3.noarch.rpm", "httpd-help-2.4.51-23.oe2203sp3.noarch.rpm" ], "aarch64": [ "httpd-2.4.51-23.oe2203sp3.aarch64.rpm", "httpd-debuginfo-2.4.51-23.oe2203sp3.aarch64.rpm", "httpd-debugsource-2.4.51-23.oe2203sp3.aarch64.rpm", "httpd-devel-2.4.51-23.oe2203sp3.aarch64.rpm", "httpd-tools-2.4.51-23.oe2203sp3.aarch64.rpm", "mod_ldap-2.4.51-23.oe2203sp3.aarch64.rpm", "mod_md-2.4.51-23.oe2203sp3.aarch64.rpm", "mod_proxy_html-2.4.51-23.oe2203sp3.aarch64.rpm", "mod_session-2.4.51-23.oe2203sp3.aarch64.rpm", "mod_ssl-2.4.51-23.oe2203sp3.aarch64.rpm" ], "src": [ "httpd-2.4.51-23.oe2203sp3.src.rpm" ], "x86_64": [ "httpd-2.4.51-23.oe2203sp3.x86_64.rpm", "httpd-debuginfo-2.4.51-23.oe2203sp3.x86_64.rpm", "httpd-debugsource-2.4.51-23.oe2203sp3.x86_64.rpm", "httpd-devel-2.4.51-23.oe2203sp3.x86_64.rpm", "httpd-tools-2.4.51-23.oe2203sp3.x86_64.rpm", "mod_ldap-2.4.51-23.oe2203sp3.x86_64.rpm", "mod_md-2.4.51-23.oe2203sp3.x86_64.rpm", "mod_proxy_html-2.4.51-23.oe2203sp3.x86_64.rpm", "mod_session-2.4.51-23.oe2203sp3.x86_64.rpm", "mod_ssl-2.4.51-23.oe2203sp3.x86_64.rpm" ] }
{ "noarch": [ "httpd-filesystem-2.4.43-26.oe2003sp4.noarch.rpm", "httpd-help-2.4.43-26.oe2003sp4.noarch.rpm" ], "aarch64": [ "httpd-2.4.43-26.oe2003sp4.aarch64.rpm", "httpd-debuginfo-2.4.43-26.oe2003sp4.aarch64.rpm", "httpd-debugsource-2.4.43-26.oe2003sp4.aarch64.rpm", "httpd-devel-2.4.43-26.oe2003sp4.aarch64.rpm", "httpd-tools-2.4.43-26.oe2003sp4.aarch64.rpm", "mod_ldap-2.4.43-26.oe2003sp4.aarch64.rpm", "mod_md-2.4.43-26.oe2003sp4.aarch64.rpm", "mod_proxy_html-2.4.43-26.oe2003sp4.aarch64.rpm", "mod_session-2.4.43-26.oe2003sp4.aarch64.rpm", "mod_ssl-2.4.43-26.oe2003sp4.aarch64.rpm" ], "src": [ "httpd-2.4.43-26.oe2003sp4.src.rpm" ], "x86_64": [ "httpd-2.4.43-26.oe2003sp4.x86_64.rpm", "httpd-debuginfo-2.4.43-26.oe2003sp4.x86_64.rpm", "httpd-debugsource-2.4.43-26.oe2003sp4.x86_64.rpm", "httpd-devel-2.4.43-26.oe2003sp4.x86_64.rpm", "httpd-tools-2.4.43-26.oe2003sp4.x86_64.rpm", "mod_ldap-2.4.43-26.oe2003sp4.x86_64.rpm", "mod_md-2.4.43-26.oe2003sp4.x86_64.rpm", "mod_proxy_html-2.4.43-26.oe2003sp4.x86_64.rpm", "mod_session-2.4.43-26.oe2003sp4.x86_64.rpm", "mod_ssl-2.4.43-26.oe2003sp4.x86_64.rpm" ] }
{ "noarch": [ "httpd-filesystem-2.4.51-23.oe2203sp1.noarch.rpm", "httpd-help-2.4.51-23.oe2203sp1.noarch.rpm" ], "aarch64": [ "httpd-2.4.51-23.oe2203sp1.aarch64.rpm", "httpd-debuginfo-2.4.51-23.oe2203sp1.aarch64.rpm", "httpd-debugsource-2.4.51-23.oe2203sp1.aarch64.rpm", "httpd-devel-2.4.51-23.oe2203sp1.aarch64.rpm", "httpd-tools-2.4.51-23.oe2203sp1.aarch64.rpm", "mod_ldap-2.4.51-23.oe2203sp1.aarch64.rpm", "mod_md-2.4.51-23.oe2203sp1.aarch64.rpm", "mod_proxy_html-2.4.51-23.oe2203sp1.aarch64.rpm", "mod_session-2.4.51-23.oe2203sp1.aarch64.rpm", "mod_ssl-2.4.51-23.oe2203sp1.aarch64.rpm" ], "src": [ "httpd-2.4.51-23.oe2203sp1.src.rpm" ], "x86_64": [ "httpd-2.4.51-23.oe2203sp1.x86_64.rpm", "httpd-debuginfo-2.4.51-23.oe2203sp1.x86_64.rpm", "httpd-debugsource-2.4.51-23.oe2203sp1.x86_64.rpm", "httpd-devel-2.4.51-23.oe2203sp1.x86_64.rpm", "httpd-tools-2.4.51-23.oe2203sp1.x86_64.rpm", "mod_ldap-2.4.51-23.oe2203sp1.x86_64.rpm", "mod_md-2.4.51-23.oe2203sp1.x86_64.rpm", "mod_proxy_html-2.4.51-23.oe2203sp1.x86_64.rpm", "mod_session-2.4.51-23.oe2203sp1.x86_64.rpm", "mod_ssl-2.4.51-23.oe2203sp1.x86_64.rpm" ] }