CLSA-2025-1760711358

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2025-1760711358
Upstream
Published
2025-10-20T14:02:40Z
Modified
2026-06-04T09:45:04.111368257Z
Summary
Fix CVE(s): CVE-2024-38474, CVE-2024-38475
Details
  • SECURITY UPDATE: modrewrite proxy handler substitution and prefixstat vulnerabilities
    • debian/patches/CVE-2024-38474-38475-*.patch: tighten up prefix_stat and %3f handling, add better question mark tracking to avoid UnsafeAllow3F
    • CVE-2024-38474, CVE-2024-38475
References

Affected packages

TuxCare:Debian:10
apache2

Package

Name
apache2
Purl
pkg:deb/tuxcare/apache2?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
apache2-bin

Package

Name
apache2-bin
Purl
pkg:deb/tuxcare/apache2-bin?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
apache2-data

Package

Name
apache2-data
Purl
pkg:deb/tuxcare/apache2-data?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
apache2-dev

Package

Name
apache2-dev
Purl
pkg:deb/tuxcare/apache2-dev?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
apache2-doc

Package

Name
apache2-doc
Purl
pkg:deb/tuxcare/apache2-doc?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
apache2-ssl-dev

Package

Name
apache2-ssl-dev
Purl
pkg:deb/tuxcare/apache2-ssl-dev?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
apache2-suexec-custom

Package

Name
apache2-suexec-custom
Purl
pkg:deb/tuxcare/apache2-suexec-custom?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
apache2-suexec-pristine

Package

Name
apache2-suexec-pristine
Purl
pkg:deb/tuxcare/apache2-suexec-pristine?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
apache2-utils

Package

Name
apache2-utils
Purl
pkg:deb/tuxcare/apache2-utils?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
libapache2-mod-md

Package

Name
libapache2-mod-md
Purl
pkg:deb/tuxcare/libapache2-mod-md?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"
libapache2-mod-proxy-uwsgi

Package

Name
libapache2-mod-proxy-uwsgi
Purl
pkg:deb/tuxcare/libapache2-mod-proxy-uwsgi?distro=debian-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.59-1~deb10u1+tuxcare.els2

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2025-1760711358.json"