SSLEngine optional 設定に注意。 "Robert Merget discovered that the Apache HTTP Server mod_ssl module incorrectly handled TLS upgrades. A remote attacker could possibly use this issue to hijack an HTTP session. This update removes the old “SSLEngine optional” configuration option, possibly requiring a configuration change in certain environments. (CVE-2025-49812)" USN-7639-1: Apache HTTP Server vulnerabilities | Ubuntu security notices | Ubuntu https://ubuntu.com/security/notices/USN-7639-1
[Mastodon] 2025-07-17 07:33:06
|