CLSA-2025-1760711358
Dashboard / Vulnerabilities / CLSA-2025-1760711358
CLSA-2025-1760711358
Published: 20 Oct 2025Last Modified: 4 Jun 2026
Upstream:
Summary: Fix CVE(s): CVE-2024-38474, CVE-2024-38475
Details: * SECURITY UPDATE: mod_rewrite proxy handler substitution and prefix_stat vulnerabilities - debian/patches/CVE-2024-38474-38475-*.patch: tighten up prefix_stat and %3f handling, add better question mark tracking to avoid UnsafeAllow3F - CVE-2024-38474, CVE-2024-38475
Affected packages
Package
Name: apache2
Purl: pkg:deb/tuxcare/apache2?distro=debian-10
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.4.59-1~deb10u1+tuxcare.els2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
