From beb98197e5f325f22460f34da83ae437ecb5c4ae Mon Sep 17 00:00:00 2001 From: Aaron Bauman Date: Wed, 27 Mar 2019 22:18:11 -0400 Subject: [ GLSA 201903-21 ] Apache: Multiple vulnerabilities Signed-off-by: Aaron Bauman --- glsa-201903-21.xml | 54 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 54 insertions(+) create mode 100644 glsa-201903-21.xml (limited to 'glsa-201903-21.xml') diff --git a/glsa-201903-21.xml b/glsa-201903-21.xml new file mode 100644 index 00000000..bfbf0939 --- /dev/null +++ b/glsa-201903-21.xml @@ -0,0 +1,54 @@ + + + + Apache: Multiple vulnerabilities + Multiple vulnerabilities have been found in Apache Web Server, the + worst of which could result in a Denial of Service condition. + + apache + 2019-03-28 + 2019-03-28 + 676064 + remote + + + 2.4.38-r1 + 2.4.38-r1 + + + +

The Apache HTTP server is one of the most popular web servers on the + Internet. +

+
+ +

Multiple vulnerabilities have been discovered in Apache. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker can possibly cause a Denial of Service condition or + could bypass mod_session_cookie expiration time. +

+
+ +

There is no known workaround at this time.

+
+ +

All Apache users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.38-r1" + + +
+ + CVE-2018-17189 + CVE-2018-17190 + CVE-2018-17199 + CVE-2019-0190 + + BlueKnight + Zlogene +
-- cgit v1.2.3-65-gdbad