system environment/daemons

httpd-tools - Tools for use with the Apache HTTP Server

Website: https://httpd.apache.org/
License: ASL 2.0
Vendor: Rocky
Description:
The httpd-tools package contains tools which can be used with
the Apache HTTP Server.

Packages

httpd-tools-2.4.37-65.module+el8.10.0+40257+286895ef.9.x86_64 [114 KiB] Changelog by Luboš Uhliarik (2026-07-09):
- Resolves: RHEL-186198 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186166 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-175620 - httpd:2.4/httpd: NULL pointer dereference via
  specially crafted request (CVE-2026-29169)
- Resolves: RHEL-186176 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-192751 - mod_proxy_html regression in CVE-2026-34355 fix
- Resolves: RHEL-193114 - httpd: Apache HTTP Server: Denial of Service
  in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
- Resolves: RHEL-186219 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-191243 - httpd: Apache HTTP Server: Out-of-bounds Read in
  mod_headers and mod_mime (CVE-2026-43951)
- Resolves: RHEL-184307 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves: RHEL-182577 - httpd: incomplete fix
  for CVE-2023-38709 (CVE-2024-42516)
httpd-tools-2.4.37-65.module+el8.10.0+40206+be2c8a50.8.x86_64 [113 KiB] Changelog by Luboš Uhliarik (2026-05-12):
- Resolves: RHEL-173558 - httpd:2.4/httpd: Apache HTTP Server mod_proxy_ajp:
  Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175074 - httpd:2.4/httpd: NULL pointer dereference can
  cause a child process crash (CVE-2026-33007)
- Resolves: RHEL-175088 - httpd:2.4/httpd: off-by-one out-of-bounds reads
  in AJP getter functions (CVE-2026-33857)
- Resolves: RHEL-175620 - httpd:2.4/httpd: NULL pointer dereference via
  specially crafted request (CVE-2026-29169)
- Resolves: RHEL-175055 - httpd: heap-based buffer over-read and memory
  disclosure in ajp_parse_data() (CVE-2026-34059)
httpd-tools-2.4.37-65.module+el8.10.0+40197+0231e209.8.x86_64 [113 KiB] Changelog by Luboš Uhliarik (2026-05-12):
- Resolves: RHEL-173558 - httpd:2.4/httpd: Apache HTTP Server mod_proxy_ajp:
  Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175074 - httpd:2.4/httpd: NULL pointer dereference can
  cause a child process crash (CVE-2026-33007)
- Resolves: RHEL-175088 - httpd:2.4/httpd: off-by-one out-of-bounds reads
  in AJP getter functions (CVE-2026-33857)
- Resolves: RHEL-175620 - httpd:2.4/httpd: NULL pointer dereference via
  specially crafted request (CVE-2026-29169)
- Resolves: RHEL-175055 - httpd: heap-based buffer over-read and memory
  disclosure in ajp_parse_data() (CVE-2026-34059)

Listing created by Repoview-0.6.6-16.el8.sme