The manufacturer Canonical has not yet set up its devicebase profile. Content such as updates, compatibilities and support may only be maintained with a delay.
Update

USN-6885-4: Apache HTTP Server regression

USN-6885-4: Apache HTTP Server regression
7 April 2025

USN-6885-1 introduced a regression in Apache HTTP Server.

Releases

  • Ubuntu 24.10
  • Ubuntu 24.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • apache2 - Apache HTTP server

Details
USN-6885-1 fixed a vulnerability in Apache. The patch
for CVE-2024-38474 was incomplete and caused regressions.
This update provides the fix for that issue.

Original advisory details:

Orange Tsai discovered that the Apache HTTP Server mod_rewrite module
incorrectly handled certain substitutions. A remote attacker could
possibly use this issue to execute scripts in directories not directly
reachable by any URL, or cause a denial of service. Some environments
may require using the new UnsafeAllow3F flag to handle unsafe
substitutions. (CVE-2024-38474)

Update instructions
The problem can be corrected by updating your system to the following package versions:

Ubuntu 24.10

  • apache2 - 2.4.62-1ubuntu1.1
    Ubuntu 24.04
  • apache2 - 2.4.58-1ubuntu8.6
    Ubuntu 22.04
  • apache2 - 2.4.52-1ubuntu4.14
    Ubuntu 20.04
  • apache2 - 2.4.41-4ubuntu3.23
    Ubuntu 18.04
  • apache2 - 2.4.29-1ubuntu4.27+esm4
    Ubuntu 16.04
  • apache2 - 2.4.18-2ubuntu3.17+esm14

In general, a standard system update will make all the necessary changes.

Version: 24.04 LTS Link
Receive Important Update Messages Stay tuned for upcoming Canonical Ubuntu Desktop updates

More from the Operating Systems section

Was the content helpful to you?

Advertisement Advertise here?
Udemy IT certification ad