-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4155-1 [email protected] https://www.debian.org/lts/security/ Moritz Schlarb May 08, 2025 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : libapache2-mod-auth-openidc Version : 2.4.9.4-0+deb11u6 CVE ID : CVE-2025-3891 Debian Bug : 1104484 A vulnerability has been fixed in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. An unauthenticated attacker can crash the Apache httpd process by sending a POST request without a Content-Type header when OIDCPreservePost is enabled in mod_auth_openidc. This leads to denial of service. A workaround is to disable the OIDCPreservePost directive. For Debian 11 bullseye, this problem has been fixed in version 2.4.9.4-0+deb11u6. We recommend that you upgrade your libapache2-mod-auth-openidc packages. For the detailed security status of libapache2-mod-auth-openidc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libapache2-mod-auth-openidc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3wEiR7/GVQGv8oRFDCS4Qcfduq8FAmgcZPUACgkQDCS4Qcfd uq8E8g/8DHbYirFPT45jZQCk9pMgREC1LLWNgo4beEp86owuZSXyDnMTI+DOECX9 q8+EFnLCFfto3dyxg7cfJ0AxQfEDZ6pSnZWdAiDOGE+WaHsgDPPmLAQ/yZFDaYQ3 6TFiNbP93bad4OFis8zcFoM6xeYbQIlAkXx7KbBdk2dOsABW/DiERwBG/FXuIdhY Dm2GR3+3bO3dxFl4abZB7he2cjXQuUJBG6NTPs6ef/AH0IvC1LR2zTKftabGOpav gbegLPsdiCkIsq1skHrkodvpf+RcrlWeEwEytLSCPJrgURb+3MA9VlSiF5XMTqSk QVlk6EXYtRPesjLbXDDzsEDKDIQOXocwHEuTAPjodZq7DD1kUDVcvllU2cEDhWTO 6BxnNXWPWadB/DOChhVYLIhRca2wHYpt0Zj277b9SoRE+bME2EtmSH94OwnBg6/G XwdttfnKFEaThRt3W1vVKiXTPa/RryySD8j6k7kVREmLi2yCRHkuWJJYs1AedF+8 o5Qac/qRD/lMvj4k5smt9rAq6sBaFpTS4u8925bNba2UqjIAxMkzRB+5f1FVc8r5 GMtmSLfCAs8q9/XDBQj+Mi6Giivartj6ms9FhGudSj16aYuLBeVfr+yvVu/WzmkA Nqg1XjMf/A+YO2FZVEh3cT0e1I+hNsEfELvaEcNRJcCS1DfNNcY= =704h -----END PGP SIGNATURE-----
