Apache: Multiple vulnerabilities — GLSA 201710-32

Multiple vulnerabilities have been found in Apache, the worst of which may result in the loss of secrets.

Affected Packages

www-servers/apache on all architectures
Affected versions < 2.4.27-r1
Unaffected versions >= 2.4.27-r1

Background

The Apache HTTP server is one of the most popular web servers on the Internet.

Description

Multiple vulnerabilities have been discovered in Apache. Please review the referenced CVE identifiers for details.

Impact

The Optionsbleed vulnerability can leak arbitrary memory from the server process that may contain secrets. Additionally attackers may cause a Denial of Service condition, bypass authentication, or cause information loss.

Workaround

There is no known workaround at this time.

Resolution

All Apache users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.27-r1"
 

References

Release Date
October 29, 2017

Latest Revision
October 29, 2017: 1

Severity
normal

Exploitable
remote

Bugzilla entries