Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws
AI-summarised brief · reviewed before publication
The Apache Software Foundation released Apache HTTP Server version 2.4.68, addressing 13 security vulnerabilities spanning multiple modules. The patched flaws include use-after-free conditions, cross-site scripting, and buffer overflows affecting all versions from 2.4.0 through 2.4.67. Administrators are urged to upgrade immediately, as no workarounds are available for most vulnerabilities. The release fixes two use-after-free vulnerabilities, an XSS flaw in mod_proxy_ftp, and four buffer overflow vulnerabilities. The updated release is available via the official Apache download page, and users are recommended to upgrade to Apache HTTP Server 2.4.68.
💡 Why It Matters
- · Immediate upgrades are crucial to prevent exploitation of these vulnerabilities, which can lead to privilege escalation and denial-of-service attacks.
- · Vulnerable servers can be compromised by malicious HTTP/2 requests or attacker-controlled backend FTP servers.