[CLSA-2026:1785417481] Fix CVE(s): CVE-2006-20001
Type:
security
Severity:
Important
Release date:
2026-07-30 13:18:14 UTC
Description:
* SECURITY UPDATE: out-of-bounds pool access in mod_dav If: header parsing - debian/patches/CVE-2006-20001.patch: confine the two-byte cursor advance to the "Not" branch and reject any other 'N'-prefixed token with HTTP 400 in dav_process_if_header() in modules/dav/main/util.c. - CVE-2006-20001
CVEs fixed:
Updated packages:
  • apache2_2.4.18-2ubuntu3.17+tuxcare.els24_amd64.deb
    sha:cb6a9025a3e60bde7d23155890ef3ae81bc0335d
  • apache2-bin_2.4.18-2ubuntu3.17+tuxcare.els24_amd64.deb
    sha:7f7bfd14f4ce154c2e03a225d6cf77f8d3c64d97
  • apache2-data_2.4.18-2ubuntu3.17+tuxcare.els24_all.deb
    sha:31c7d5904e7388473956cb998cb121580948d5e9
  • apache2-dev_2.4.18-2ubuntu3.17+tuxcare.els24_amd64.deb
    sha:c6b0903972e527c0d7c5a9f4fc5fc52c843d58b8
  • apache2-doc_2.4.18-2ubuntu3.17+tuxcare.els24_all.deb
    sha:51a0c6517a9ded5fb2a5868f5f4ec9368f42d34a
  • apache2-suexec-custom_2.4.18-2ubuntu3.17+tuxcare.els24_amd64.deb
    sha:60bc9bb5ed4203bd21505c257576c773d2e1194c
  • apache2-suexec-pristine_2.4.18-2ubuntu3.17+tuxcare.els24_amd64.deb
    sha:dee68baa499d7127a21053a5b4c5773ecc42bb73
  • apache2-utils_2.4.18-2ubuntu3.17+tuxcare.els24_amd64.deb
    sha:ea8984d341b4b1efd98fe9c660cfe4cff1251151
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.