Alert GCSA-19039 - Vulnerabilita' in Apache HTTP Server
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ****************************************************************** Alert ID : GCSA-19039 Data : 5 Aprile 2019 Titolo : Vulnerabilita' in Apache HTTP Server ****************************************************************** :: Descrizione del problema E' stata rilasciata una nuova versione del server HTTP Apache con la quale vengono risolte varie vulnerabilita'. :: Software interessato Apache HTTP Server 2.4.38 e precedenti su sistemi Unix/Linux :: Impatto Denial of service Escalation di privilegi Compromissione della macchina :: Soluzioni Aggiornare Apache all'ultima versione 2.4.39 http://httpd.apache.org/download.cgi :: Riferimenti Apache http://httpd.apache.org/security/vulnerabilities_24.html US-CERT https://www.us-cert.gov/ncas/current-activity/2019/04/04/Apache-Releases-Security-Update-Apache-HTTP-Server CERT Nazionale https://www.certnazionale.it/news/2019/04/03/vulnerabilita-multiple-in-apache-http-server/ Debian https://www.debian.org/security/2019/dsa-4422 Ubuntu https://usn.ubuntu.com/3937-1/ Mitre's CVE ID http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0211 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0217 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0215 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0197 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0196 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0220 GARR CERT Newsletter subscribe/unsubscribe: http://www.cert.garr.it/alert/ricevi-gli-alert-di-cert -----BEGIN PGP SIGNATURE----- iF0EARECAB0WIQTGpdiR5MqstacBGHbBnEyTZRJgQgUCXKcZGQAKCRDBnEyTZRJg QqlaAJ4/2g9iUVwFx15ovS3cv8W2B7q4TQCdGOH/mc96xavBXMKNCeRZcrJLa4A= =cE3M -----END PGP SIGNATURE-----