Vulnerability Database
Blog
FAQ
Docs
RHSA-2017:3018
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2017:3018
Import Source
https://security.access.redhat.com/data/osv/RHSA-2017:3018.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2017:3018
Related
CVE-2017-9798
Published
2024-09-13T16:49:11Z
Modified
2024-09-13T16:49:11Z
Severity
5.9 (Medium)
CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Calculator
Summary
Red Hat Security Advisory: httpd24 security, bug fix, and enhancement update
Details
References
https://access.redhat.com/errata/RHSA-2017:3018
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-US/Red_Hat_Software_Collections/3/html/3.0_Release_Notes/chap-RHSCL.html#sect-RHSCL-Changes-httpd
https://bugzilla.redhat.com/show_bug.cgi?id=1327548
https://bugzilla.redhat.com/show_bug.cgi?id=1418395
https://bugzilla.redhat.com/show_bug.cgi?id=1428940
https://bugzilla.redhat.com/show_bug.cgi?id=1440858
https://bugzilla.redhat.com/show_bug.cgi?id=1457316
https://bugzilla.redhat.com/show_bug.cgi?id=1480506
https://bugzilla.redhat.com/show_bug.cgi?id=1486843
https://bugzilla.redhat.com/show_bug.cgi?id=1487164
https://bugzilla.redhat.com/show_bug.cgi?id=1488541
https://bugzilla.redhat.com/show_bug.cgi?id=1490344
https://access.redhat.com/security/data/csaf/v2/advisories/2017/rhsa-2017_3018.json
https://access.redhat.com/security/cve/CVE-2017-9798
https://www.cve.org/CVERecord?id=CVE-2017-9798
https://nvd.nist.gov/vuln/detail/CVE-2017-9798
https://blog.fuzzing-project.org/60-Optionsbleed-HTTP-OPTIONS-method-can-leak-Apaches-server-memory.html
Affected packages
Red Hat:rhel_software_collections:3::el6
/
httpd24
Package
Name
httpd24
Purl
pkg:rpm/redhat/httpd24
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.1-18.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-httpd
Package
Name
httpd24-httpd
Purl
pkg:rpm/redhat/httpd24-httpd
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-httpd-debuginfo
Package
Name
httpd24-httpd-debuginfo
Purl
pkg:rpm/redhat/httpd24-httpd-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-httpd-devel
Package
Name
httpd24-httpd-devel
Purl
pkg:rpm/redhat/httpd24-httpd-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-httpd-manual
Package
Name
httpd24-httpd-manual
Purl
pkg:rpm/redhat/httpd24-httpd-manual
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-httpd-tools
Package
Name
httpd24-httpd-tools
Purl
pkg:rpm/redhat/httpd24-httpd-tools
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-mod_ldap
Package
Name
httpd24-mod_ldap
Purl
pkg:rpm/redhat/httpd24-mod_ldap
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-mod_proxy_html
Package
Name
httpd24-mod_proxy_html
Purl
pkg:rpm/redhat/httpd24-mod_proxy_html
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.4.27-8.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-mod_session
Package
Name
httpd24-mod_session
Purl
pkg:rpm/redhat/httpd24-mod_session
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-mod_ssl
Package
Name
httpd24-mod_ssl
Purl
pkg:rpm/redhat/httpd24-mod_ssl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.4.27-8.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-runtime
Package
Name
httpd24-runtime
Purl
pkg:rpm/redhat/httpd24-runtime
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.1-18.el6
Red Hat:rhel_software_collections:3::el6
/
httpd24-scldevel
Package
Name
httpd24-scldevel
Purl
pkg:rpm/redhat/httpd24-scldevel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.1-18.el6
Red Hat:rhel_software_collections:3::el7
/
httpd24
Package
Name
httpd24
Purl
pkg:rpm/redhat/httpd24
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.1-18.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-curl
Package
Name
httpd24-curl
Purl
pkg:rpm/redhat/httpd24-curl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.47.1-4.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-curl-debuginfo
Package
Name
httpd24-curl-debuginfo
Purl
pkg:rpm/redhat/httpd24-curl-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.47.1-4.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-httpd
Package
Name
httpd24-httpd
Purl
pkg:rpm/redhat/httpd24-httpd
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-httpd-debuginfo
Package
Name
httpd24-httpd-debuginfo
Purl
pkg:rpm/redhat/httpd24-httpd-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-httpd-devel
Package
Name
httpd24-httpd-devel
Purl
pkg:rpm/redhat/httpd24-httpd-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-httpd-manual
Package
Name
httpd24-httpd-manual
Purl
pkg:rpm/redhat/httpd24-httpd-manual
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-httpd-tools
Package
Name
httpd24-httpd-tools
Purl
pkg:rpm/redhat/httpd24-httpd-tools
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-libcurl
Package
Name
httpd24-libcurl
Purl
pkg:rpm/redhat/httpd24-libcurl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.47.1-4.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-libcurl-devel
Package
Name
httpd24-libcurl-devel
Purl
pkg:rpm/redhat/httpd24-libcurl-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:7.47.1-4.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-libnghttp2
Package
Name
httpd24-libnghttp2
Purl
pkg:rpm/redhat/httpd24-libnghttp2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.1-6.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-libnghttp2-devel
Package
Name
httpd24-libnghttp2-devel
Purl
pkg:rpm/redhat/httpd24-libnghttp2-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.1-6.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-mod_auth_kerb
Package
Name
httpd24-mod_auth_kerb
Purl
pkg:rpm/redhat/httpd24-mod_auth_kerb
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.4-33.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-mod_auth_kerb-debuginfo
Package
Name
httpd24-mod_auth_kerb-debuginfo
Purl
pkg:rpm/redhat/httpd24-mod_auth_kerb-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:5.4-33.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-mod_ldap
Package
Name
httpd24-mod_ldap
Purl
pkg:rpm/redhat/httpd24-mod_ldap
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-mod_proxy_html
Package
Name
httpd24-mod_proxy_html
Purl
pkg:rpm/redhat/httpd24-mod_proxy_html
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.4.27-8.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-mod_session
Package
Name
httpd24-mod_session
Purl
pkg:rpm/redhat/httpd24-mod_session
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:2.4.27-8.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-mod_ssl
Package
Name
httpd24-mod_ssl
Purl
pkg:rpm/redhat/httpd24-mod_ssl
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1:2.4.27-8.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-nghttp2
Package
Name
httpd24-nghttp2
Purl
pkg:rpm/redhat/httpd24-nghttp2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.1-6.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-nghttp2-debuginfo
Package
Name
httpd24-nghttp2-debuginfo
Purl
pkg:rpm/redhat/httpd24-nghttp2-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.7.1-6.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-runtime
Package
Name
httpd24-runtime
Purl
pkg:rpm/redhat/httpd24-runtime
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.1-18.el7
Red Hat:rhel_software_collections:3::el7
/
httpd24-scldevel
Package
Name
httpd24-scldevel
Purl
pkg:rpm/redhat/httpd24-scldevel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:1.1-18.el7
RHSA-2017:3018 - OSV