Apache: Multiple vulnerabilities Multiple vulnerabilities have been found in Apache, the worst of which may result in the loss of secrets. Apache 2017-10-29 2017-10-29 622240 624868 631308 remote 2.4.27-r1 2.4.27-r1

The Apache HTTP server is one of the most popular web servers on the Internet.

Multiple vulnerabilities have been discovered in Apache. Please review the referenced CVE identifiers for details.

The Optionsbleed vulnerability can leak arbitrary memory from the server process that may contain secrets. Additionally attackers may cause a Denial of Service condition, bypass authentication, or cause information loss.

There is no known workaround at this time.

All Apache users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.27-r1"
CVE-2017-3167 CVE-2017-3169 CVE-2017-7659 CVE-2017-7668 CVE-2017-7679 CVE-2017-9788 CVE-2017-9789 CVE-2017-9798 jmbailey jmbailey