stable

httpd-2.4.34-3.fc28

FEDORA-2018-49d3b42425 created by jorton 7 years ago for Fedora 28

This update includes the latest upstream release, httpd 2.4.34, with multiple bug fixes and enhancements. See http://www.apache.org/dist/httpd/CHANGES_2.4.34 for more information on the changes in this version.

A security vulnerability is addressed in this update:

  • mod_md: DoS via Coredumps on specially crafted requests (CVE-2018-8011)

The following changes are also included in this update:

  • The post-transaction scriptlet to restart httpd.service no longer blocks waiting for the restart to complete.
  • mod_ssl now supports loading private keys (and associated certificates) from a PKCS#11 provider. Use a pkcs11: URI in the SSLCertificateKeyFile (and optionally SSLCertificateFile) directive(s).
  • An example Lua-based server-status.conf is packaged in the docdir
  • httpd now Obsoletes mod_proxy_uwsgi (#1599113)
  • mod_systemd now logs listening ports at startup

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2018-49d3b42425

This update has been submitted for testing by jorton.

7 years ago

jorton edited this update.

7 years ago

jorton edited this update.

7 years ago

hello jorton, according to apache httpd changelog https://www.apache.org/dist/httpd/CHANGES_2.4.34 there is also CVE-2018-1333 fixed within this release. can you confirm this?

regards, muench

CVE-2018-1333 is a mod_md issue and in Fedora we ship mod_md separately from github releases.

CVE-2018-1333 is fixed by http://svn.apache.org/viewvc?view=revision&revision=1828879 (confirmed with security@httpd.apache.org)

This change is mirrored to github here: https://github.com/icing/mod_h2/commit/83a2e3866918ce6567a683eb4c660688d047ee81

That github commit is present in tag for mod_md 1.10.18. We already updated to 1.10.18 in Fedora, so Fedora users have the fix already. FEDORA-2018-54fed84dcd

Thank you jorton,

CVE-2018-1333 is a mod_md issue and in Fedora we ship mod_md separately from github releases. I assume you mean 'mod_h2'? 'mod_md' is concerned by CVE-2018-8011

Sorry! Yes I mean mod_http2/mod_h2.

This update has been pushed to testing.

7 years ago
User Icon bojan commented & provided feedback 7 years ago
karma

Works here.

User Icon cserpentis commented & provided feedback 7 years ago
karma

works for me

User Icon pwalter commented & provided feedback 7 years ago
karma

Works

NOTE: DO NOT PUSH THIS TO STABLE.

There is a regression upstream which I will integrate the fix for, plus the Obsoletes for mod_proxy_uwsgi needs to be updated.

jorton edited this update.

7 years ago

jorton edited this update.

New build(s):

  • httpd-2.4.34-3.fc28

Removed build(s):

  • httpd-2.4.34-1.fc28

Karma has been reset.

7 years ago

This update has been submitted for testing by jorton.

7 years ago

jorton edited this update.

7 years ago

This update has been pushed to testing.

7 years ago
User Icon fdelapena commented & provided feedback 7 years ago
karma

Works for me.

jorton edited this update.

7 years ago
User Icon besser82 commented & provided feedback 7 years ago
karma

Works great! LGTM! =)

User Icon carlwgeorge commented & provided feedback 7 years ago
karma

The obsoletes for #1599113 look good to me.

This update has reached the stable karma threshold and can be pushed to stable now if the maintainer wishes.

7 years ago

This update has been submitted for batched by jorton.

7 years ago

This update has been submitted for stable by bodhi.

7 years ago

This update has been pushed to stable.

7 years ago

Please log in to add feedback.

Metadata
Type
security
Severity
low
Karma
3
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
disabled
Stable by Time
disabled
Dates
submitted
7 years ago
in testing
7 years ago
in stable
7 years ago
modified
7 years ago
BZ#1599113 httpd: obsolete mod_proxy_uwsgi
0
0
BZ#1601160 httpd-2.4.34 is available
0
0
BZ#1605052 CVE-2018-8011 httpd: mod_md: NULL pointer dereference causing httpd child process crash
0
0
BZ#1605093 CVE-2018-8011 httpd: mod_md: NULL pointer dereference causing httpd child process crash [fedora-all]
0
0

Automated Test Results

Test Cases

0 0 Test Case HTTPd