Opened 4 months ago
Closed 2 months ago
#23430 closed enhancement (fixed)
httpd-2.4.68
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (4)
comment:1 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Priority: | normal → elevated |
| Status: | assigned → new |
comment:3 by , 3 months ago
| Milestone: | 13.1 → 98-Security |
|---|
comment:4 by , 2 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-163 has been issued.
Note:
See TracTickets
for help on using tickets.

CVE's fixed in this release:
merge_response_headerscan cause crash (CVE-2026-43951)send_request(CVE-2026-44185)proxy_ftp_handlerin mod_proxy_ftp (CVE-2026-44186)ap_regnamevia Signed Char Overflow (CVE-2026-44631)https://httpd.apache.org/security/vulnerabilities_24.html
Changes with Apache 2.4.68 *) mod_ssl, ab: Add support for OpenSSL 4.0. [Joe Orton] *) mod_ssl: Add SerialNumber as a recognized attribute type for SSL distinguished name variables. [Michael Osipov <michaelo apache.org>, Benjamin Demarteau <benjamin.demarteau liege.be>] *) mod_ssl: Set auth type to "ClientCert" when client certificate authentication has been performed. [Michael Osipov <michaelo apache.org>] *) mod_include: Don't print any of if/elsif/else content when a conditional evaluation returns an error. [Eric Covener] *) mod_unixd: CoreDumpDirectory requires enabling tracing on FreeBSD 11+. PR 65819. [David CARLIER <devnexen gmail.com>] *) mod_file_cache: Fix crashes for mmap'ed files under threaded MPMs. PR 69901. barr.israel <barr.israel campus.technion.ac.il> *) core: Add support for %{m}t in ErrorLogFormat to log milli-second time resolution (in addition to existing %{u}t for micro-seconds). [Luboš Uhliarik <luhliari redhat.com>] *) mod_unixd: Drop test that effective user ID is zero in a chroot configuration. PR 69767. [Bastien Roucaries <rouca debian.org>] *) mod_proxy_balancer: Include nonce in XML output. PR 63074. Federico Mennite <federico.mennite lifeware.ch> *) mod_http2: update to version 2.0.42 Fix excessive file description use for non-TLS frontend connections when sending files. Fixes <https://github.com/icing/mod_h2/issues/325> [Stefan Eissing] *) mod_http2: update to version 2.0.41 Fix cookie header accounting against LimitRequestFields. [Stefan Eissing] *) mod_http2: update to version 2.0.40 Fix error handling on upload requests when server runs out of file handles that left beam bucket callbacks in place, potentially using no longer valid references. Only applies on platforms with pipes and file descriptor limits not healthy for a network server. [Stefan Eissing] *) mod_dav_fs: Return a 404 for DELETE if deletion fails because the resource no longer exists. PR 60746. [Joe Orton] *) mod_proxy_hcheck: Fix healthcheck disabled due to child restart while updating. [Yann Ylavic]Fixed at 321d4963ed. Leaving open for SA.