Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

mod_ssl-2.4.63-16.el10 RPM for aarch64

From CentOS Stream 10 AppStream for aarch64

Name: mod_ssl Distribution: CentOS
Version: 2.4.63 Vendor: CentOS
Release: 16.el10 Build date: Tue Aug 25 11:17:24 2026
Group: Unspecified Build host: aarch64-03.stream.rdu2.redhat.com
Size: 278982 Source RPM: httpd-2.4.63-16.el10.src.rpm
Packager: builder@centos.org
Url: https://httpd.apache.org/
Summary: SSL/TLS module for the Apache HTTP Server
The mod_ssl module provides strong cryptography for the Apache HTTP
server via the Secure Sockets Layer (SSL) and Transport Layer
Security (TLS) protocols.

Provides

Requires

License

Apache-2.0 AND (BSD-3-Clause AND metamail AND HPND-sell-variant AND Spencer-94)

Changelog

* Tue Aug 25 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-16
  - Resolves: RHEL-190819 - httpd: Apache HTTP Server: Arbitrary code
    execution or denial of service via use-after-free in mod_ldap per-directory
    configuration (CVE-2026-29167)
* Tue Aug 18 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-15
  - Resolves: RHEL-186222 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
    via malicious backend servers (CVE-2026-34356)
  - Resolves: RHEL-186190 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
    via untrusted content in mod_xml2enc (CVE-2026-42536)
  - Resolves: RHEL-186181 - httpd: Apache HTTP Server: Buffer overflow in
    mod_proxy_html allows security bypass (CVE-2026-34355)
  - Resolves: RHEL-186160 - httpd: Apache HTTP Server: Buffer Over-read via
    outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
  - Resolves: RHEL-184308 - httpd: Apache HTTP Server: Denial of Service via
    crafted regular expressions (CVE-2026-44631)
  - Resolves : RHEL-182579 - httpd: incomplete fix for
    CVE-2023-38709 (CVE-2024-42516)
  - Resolves: RHEL-175622 - httpd: NULL pointer dereference via specially crafted
    request (CVE-2026-29169)
  - Resolves: RHEL-193112 - httpd: Apache HTTP Server: Denial of Service in
    mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
  - Resolves: RHEL-234657 - httpd: Apache HTTP Server: Privilege Escalation via
    .htaccess file manipulation (CVE-2026-24072)
  - Resolves: RHEL-191241 - httpd: Apache HTTP Server: Out-of-bounds Read in
    mod_headers and mod_mime (CVE-2026-43951)
  - Also addresses CVE-2026-44119, CVE-2026-42535, CVE-2026-33006
* Fri May 29 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-14
  - Resolves: RHEL-173559 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary
    code execution via heap-based buffer overflow (CVE-2026-28780)
  - Resolves: RHEL-175064 - httpd: NULL pointer dereference can cause a child
    process crash (CVE-2026-33007)
  - Resolves: RHEL-175087 - httpd: off-by-one out-of-bounds reads in AJP getter
    functions (CVE-2026-33857)
  - Resolves: RHEL-175044 - httpd: heap-based buffer over-read due to missing
    null-termination check (CVE-2026-34032)
  - Resolves: RHEL-175060 - httpd: heap-based buffer over-read and memory
    disclosure in ajp_parse_data() (CVE-2026-34059)
* Thu Feb 12 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-13
  - Resolves: RHEL-145713 - [RFE] Need miliseconds time stamp in ErrorLogFormat
* Fri Jan 02 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-12
  - Resolves: RHEL-135053 - httpd: Apache HTTP Server: mod_userdir+suexec bypass
    via AllowOverride FileInfo (CVE-2025-66200)
  - Resolves: RHEL-135036 - httpd: Apache HTTP Server: CGI environment variable
    override (CVE-2025-65082)
  - Resolves: RHEL-134468 - httpd: Apache HTTP Server: Server Side Includes adds
    query string to #exec cmd=... (CVE-2025-58098)
* Thu Dec 18 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-11
  - Resolves: RHEL-131829 - Fix error page messaging when error handling fails
* Thu Nov 06 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-10
  - Resolves: RHEL-125880 - mod_ssl: allow more fine grained SSL SNI vhost check
    to avoid unnecessary 421 errors after CVE-2025-23048 fix
* Fri Oct 24 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-6
  - Resolves: RHEL-122290 - mod_proxy_hcheck may stop healthchecks after a child
    process is reclaimed
* Mon Sep 08 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-5
  - Resolves: RHEL-92663 - Image mode: The dir /var/www is not created when
    updating system in image mode
* Sat Aug 16 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-4
  - Resolves: RHEL-99945 - httpd: HTTP Session Hijack via a TLS
    upgrade (CVE-2025-49812)
  - Resolves: RHEL-99962 - httpd: access control bypass by trusted clients
    is possible using TLS 1.3 session resumption (CVE-2025-23048)
  - Resolves: RHEL-99970 - httpd: insufficient escaping of user-supplied
    data in mod_ssl (CVE-2024-47252)
  - Resolves: RHEL-103489 - stickysession field does not work when
    specifying it in the query parameter after upgrade to 9.5
* Mon Jul 28 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-3
  - Resolves: RHEL-106043 - httpd 2.4.62: mod_proxy_connect prematurely closes
    connections
* Thu Jul 24 2025 Joe Orton  <jorton@redhat.com> - 2.4.63-2
  - mod_dav: add dav_get_base_path() API
    Resolves: RHEL-105255
* Mon Jan 27 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.63-1
  - new version 2.4.63
  - Resolves: RHEL-76358 - httpd rebase to 2.4.63
  - Resolves: RHEL-73414 - RewriteRule proxying to UDS (unix domain socket)
    configured in .htaccess doesn't work on httpd-2.4.62-1
  - Resolves: RHEL-66489 - Apache HTTPD no longer parse PHP files with unicode
    characters in the name
* Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 2.4.62-5
  - Bump release for October 2024 mass rebuild:
    Resolves: RHEL-64018

Files

/etc/httpd/conf.d/ssl.conf
/etc/httpd/conf.modules.d/00-ssl.conf
/usr/lib/.build-id
/usr/lib/.build-id/27/a80764e6705bf6d60fd8d1fc8c48275b2cd6e3
/usr/lib/systemd/system/httpd-init.service
/usr/lib/systemd/system/httpd.socket.d/10-listen443.conf
/usr/lib64/httpd/modules/mod_ssl.so
/usr/libexec/httpd-ssl-gencerts
/usr/libexec/httpd-ssl-pass-dialog
/usr/share/man/man8/httpd-init.service.8.gz
/var/cache/httpd/ssl


Generated by rpm2html 1.8.1

Fabrice Bellet, Thu Aug 27 05:21:45 2026