elsa-2021-3816
oracle_linux
Description
httpd [2.4.37-39.1.0.1.1] - Set vstring per ORACLE_SUPPORT_PRODUCT [Orabug: 29892262] - Replace index.html with Oracle's index page oracle_index.html [2.4.37-39.1] - Resolves: #2007234 - CVE-2021-40438 httpd:2.4/httpd: mod_proxy: SSRF via a crafted request uri-path - Resolves: #2007646 - CVE-2021-26691 httpd:2.4/httpd: Heap overflow in mod_session
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2021-26691",
"CVE-2021-40438"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "httpd\n[2.4.37-39.1.0.1.1]\n- Set vstring per ORACLE_SUPPORT_PRODUCT [Orabug: 29892262]\n- Replace index.html with Oracle's index page oracle_index.html\n\n[2.4.37-39.1]\n- Resolves: #2007234 - CVE-2021-40438 httpd:2.4/httpd: mod_proxy: SSRF via\n a crafted request uri-path\n- Resolves: #2007646 - CVE-2021-26691 httpd:2.4/httpd: Heap overflow in\n mod_session",
"id": "ELSA-2021-3816",
"ovalId": "oval:com.oracle.elsa:def:20213816",
"source": "oracle_linux",
"title": "ELSA-2021-3816: httpd:2.4 security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2021-3816.html"
}