AIX Open Source

AIX Open Source

Share your experiences and connect with fellow developers to discover how to build and manage open source software for the AIX operating system

 View Only
  • 1.  apache httpd 2.4.59 has been released ,pls update it

    Posted Mon April 08, 2024 01:22 AM
    Edited by De Quan Qu Wed April 10, 2024 03:16 AM

    Apache 2.4.x < 2.4.59 Multiple Vulnerabilities , so need update from 2.4.58 to 2.4.59  Due date: May 6, 2024

    The version of Apache httpd installed on the remote host is prior to 2.4.59. It is, therefore, affected by multiple vulnerabilities as referenced in the 2.4.59 advisory.
    
      - Apache HTTP Server: HTTP Response Splitting in multiple modules: HTTP Response splitting in multiple     modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend     applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version     2.4.59, which fixes this issue. Acknowledgements: (CVE-2024-24795)
    
      - Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames: HTTP/2 incoming     headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP     413 response. If a client does not stop sending headers, this leads to memory exhaustion.
        Acknowledgements: finder: Bartek Nowotarski (https://nowotarski.info/) (CVE-2024-27316)
    
    Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

    Thanks.

    ------------------------------
    De Quan Qu
    ------------------------------



  • 2.  RE: apache httpd 2.4.59 has been released ,pls update it

    Posted Tue April 16, 2024 09:52 PM

    @RESHMA KUMAR 



    ------------------------------
    De Quan Qu
    ------------------------------



  • 3.  RE: apache httpd 2.4.59 has been released ,pls update it

    Posted Wed April 17, 2024 03:23 AM

    Thanks for reporting it. We are working on this version of httpd(2.4.59) and will be publishing it by this week.



    ------------------------------
    RESHMA KUMAR
    ------------------------------