Updated apache-mod_auth_openidc packages fix security vulnerability
Publication date: 22 Mar 2024Modification date: 21 Mar 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-24814
Description
Missing input validation on mod_auth_openidc_session_chunks cookie value makes the server vulnerable to DoS attack. (CVE-2024-24814)
References
- https://bugs.mageia.org/show_bug.cgi?id=32928
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T7DKVEVREYAI4F46CQAVOTPL75WLOZOE/
- https://github.com/OpenIDC/mod_auth_openidc/security/advisories/GHSA-hxr6-w4gc-7vvv
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24814
SRPMS
9/core
- apache-mod_auth_openidc-2.4.13.2-1.1.mga9