Debian 9911 Published by

An apache2 security update has been released for Debian GNU/Linux 8 Extended LTS to address several vulnerabilities.



ELA-456-1 apache2 security update

Package apache2
Version 2.4.10-10+deb8u18
Related CVEs CVE-2020-1927 CVE-2020-1934 CVE-2020-35452 CVE-2021-26690 CVE-2021-26691 CVE-2021-30641

Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service. In addition the implementation of the MergeSlashes option could result in unexpected behaviour.

For Debian 8 jessie, these problems have been fixed in version 2.4.10-10+deb8u18.

We recommend that you upgrade your apache2 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-456-1 apache2 security update