Alert GCSA-21102 - Vulnerabilita' in Apache HTTP server

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

******************************************************************

Alert ID: GCSA-21102
Data: 20 settembre 2021
Titolo: Vulnerabilita' in Apache HTTP server

******************************************************************

:: Descrizione del problema

E' stata rilasciata una nuova versione del server HTTP Apache
con la quale vengono risolte varie vulnerabilita'.


:: Software interessato

Apache HTTP Server versione dalla 2.4.17 alla 2.4.48


:: Impatto

Denial of Service (DoS)
Spoofing
Information Disclosure (ID)
Security Restriction Bypass (SRB)


:: Soluzioni

Aggiornare Apache all'ultima versione 2.4.49
http://httpd.apache.org/download.cgi


:: Riferimenti

Apache
http://httpd.apache.org/security/vulnerabilities_24.html

Mitre's CVE ID
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33193
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34798
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36160
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39275
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40438



GARR CERT Security Alert - subscribe/unsubscribe:
https://www.cert.garr.it/alert/ricevi-gli-alert-di-cert

-----BEGIN PGP SIGNATURE-----

iD8DBQFhSICpwZxMk2USYEIRAlvQAJ41d6RcF0MnsuKHrf1FiB9WIAIqAQCbBHEv
OCvdY4WBIaQudPLiz8nNXw4=
=3kk3
-----END PGP SIGNATURE-----