| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: httpd-tools | Distribution: CentOS |
| Version: 2.4.62 | Vendor: CentOS |
| Release: 15.el9 | Build date: Thu Aug 20 12:01:06 2026 |
| Group: Unspecified | Build host: aarch64-05.stream.rdu2.redhat.com |
| Size: 451097 | Source RPM: httpd-2.4.62-15.el9.src.rpm |
| Packager: builder@centos.org | |
| Url: https://httpd.apache.org/ | |
| Summary: Tools for use with the Apache HTTP Server | |
The httpd-tools package contains tools which can be used with the Apache HTTP Server.
ASL 2.0
* Tue Aug 18 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-15
- Resolves: RHEL-192753 - mod_proxy_html regression in CVE-2026-34355 fix
- Resolves: RHEL-186226 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-182580 - httpd: incomplete fix
for CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-186187 - httpd: mod_proxy_html buffer handling
vulnerability (CVE-2026-34355)
- Resolves: RHEL-175632 - httpd: mod_dav_lock uses wrong lock discovery
(CVE-2026-29169)
- Resolves: RHEL-186189 - mod_xml2enc: fix bblen accounting in fix_skipto
(CVE-2026-42536)
- Resolves: RHEL-186156 - httpd: fix OCSP write buffer advancement
bug in mod_ssl (CVE-2026-44185)
- Resolves: RHEL-191249 - httpd: Apache HTTP Server: Out-of-bounds Read in
mod_headers and mod_mime (CVE-2026-43951)
- Resolves: RHEL-193128 - httpd: Apache HTTP Server: Denial of Service in
mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
- Also addresses CVE-2026-24072, CVE-2026-33006, CVE-2026-42535, CVE-2026-44119
* Fri May 29 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-14
- Resolves: RHEL-173563 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary
code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175078 - httpd: NULL pointer dereference can cause a child
process crash (CVE-2026-33007)
- Resolves: RHEL-175099 - httpd: off-by-one out-of-bounds reads in AJP getter
functions (CVE-2026-33857)
- Resolves: RHEL-175035 - httpd: heap-based buffer over-read due to missing
null-termination check (CVE-2026-34032)
- Resolves: RHEL-175063 - httpd: heap-based buffer over-read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)
* Thu Feb 12 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-13
- Resolves: RHEL-129692 - [RFE] Need miliseconds time stamp in ErrorLogFormat
* Thu Jan 08 2026 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-12
- Resolves: RHEL-135064 - httpd: Apache HTTP Server: mod_userdir+suexec bypass
via AllowOverride FileInfo (CVE-2025-66200)
- Resolves: RHEL-135049 - httpd: Apache HTTP Server: CGI environment variable
override (CVE-2025-65082)
- Resolves: RHEL-134481 - httpd: Apache HTTP Server: Server Side Includes adds
query string to #exec cmd=... (CVE-2025-58098)
* Fri Dec 19 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-11
- Resolves: RHEL-131827 - Fix error page messaging when error handling fails
* Thu Nov 06 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-10
- Resolves: RHEL-119000 - mod_ssl: allow more fine grained SSL SNI vhost check
to avoid unnecessary 421 errors after CVE-2025-23048 fix
- mod_ssl: add conf.d/snipolicy.conf to set 'SSLVHostSNIPolicy authonly' default
* Fri Oct 24 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-9
- Resolves: RHEL-105446 - mod_proxy_hcheck may stop healthchecks after a child
process is reclaimed
* Mon Oct 13 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-8
- Resolves: RHEL-114501 Image mode: The dir /var/www is not created when
updating system in image mode
* Sat Aug 16 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-7
- Resolves: RHEL-99815 - stickysession field does not work when specifying
it in the query parameter after upgrade to 9.5
- Resolves: RHEL-99953 - httpd: HTTP Session Hijack via a TLS
upgrade (CVE-2025-49812)
- Resolves: RHEL-99968 - httpd: access control bypass by trusted
clients is possible using TLS 1.3 session resumption (CVE-2025-23048)
- Resolves: RHEL-99977 - httpd: insufficient escaping of user-supplied
data in mod_ssl (CVE-2024-47252)
* Tue Jul 29 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-6
- Resolves: RHEL-94562 - httpd 2.4.62: mod_proxy_connect prematurely closes
connections
* Fri Jun 06 2025 Joe Orton <jorton@redhat.com> - 2.4.62-5
- mod_dav: add dav_get_base_path() API
- Resolves: RHEL-41069
* Wed Jan 29 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-4
- Resolves: RHEL-66488 - Apache HTTPD no longer parse PHP files with unicode
characters in the name
* Thu Jan 09 2025 Luboš Uhliarik <luhliari@redhat.com> - 2.4.62-3
- Resolves: RHEL-68660 - RewriteRule proxying to UDS (unix domain socket)
configured in .htaccess doesn't work on httpd-2.4.62-1
* Thu Sep 12 2024 Joe Orton <jorton@redhat.com> - 2.4.62-2
- mod_ssl: fix loading keys via ENGINE API
Resolves: RHEL-36755
/usr/bin/ab /usr/bin/htdbm /usr/bin/htdigest /usr/bin/htpasswd /usr/bin/httxt2dbm /usr/bin/logresolve /usr/lib/.build-id /usr/lib/.build-id/00 /usr/lib/.build-id/00/4d3678a24e83b17c9fd1609982996719a1a547 /usr/lib/.build-id/68/f08f72c611cc1bca3be9353b91cc3796215b0f /usr/lib/.build-id/6e/bc49dca9d751f274dbec2f4c295fb8f8fd35b6 /usr/lib/.build-id/c0 /usr/lib/.build-id/c0/53f904f5f875ee0328fe7afd54a01dbe85008a /usr/lib/.build-id/c7 /usr/lib/.build-id/c7/1d0e75450d1ef1f577da2bf151f51734411403 /usr/lib/.build-id/de/458f19847ef9ce4903130180e04a30d2263a21 /usr/share/doc/httpd-tools /usr/share/doc/httpd-tools/LICENSE /usr/share/doc/httpd-tools/NOTICE /usr/share/man/man1/ab.1.gz /usr/share/man/man1/htdbm.1.gz /usr/share/man/man1/htdigest.1.gz /usr/share/man/man1/htpasswd.1.gz /usr/share/man/man1/httxt2dbm.1.gz /usr/share/man/man1/logresolve.1.gz
Generated by rpm2html 1.8.1
Fabrice Bellet, Thu Aug 27 05:00:22 2026