Debian Security Update DSA-5917-1 libapache2-mod-auth-openidc - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,811
Reaction score
74
Credits
-1,257
A vulnerability has been discovered in mod_auth_openidc, an OpenID Certified authentication and authorization module for the Apache HTTP server that implements the OpenID Connect Relying Party functionality:
An unauthenticated attacker could crash the Apache httpd process by sending a POST request without a Content-Type header if the 'OIDCPreservePost' directive is enabled, resulting in denial of service.
https://security-tracker.debian.org/tracker/DSA-5917-1

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top