LENA 1.3.3 fix#9 릴리스 노트
LENA 1.3.3 fix#9의 변경 항목과 상세 수정 사항입니다.
|LENA 기술지원
releasev1.3.3fix-9changelog
변경 항목
- Web Server
- Web Application Server
상세 내용
Web Server
(WEB-A)
- CVE-2026-29167 mod_ldap per-directory use-after-free 취약점 해결
- CVE-2026-29170 mod_proxy_ftp XSS 취약점 해결
- CVE-2026-34355 mod_proxy_html buffer overflow 취약점 해결
- CVE-2026-34356 ProxyPassReverseCookieMap buffer overflow 취약점 해결
- CVE-2026-42535 mod_dav_fs 보호 디렉터리 접근 취약점 해결
- CVE-2026-42536 mod_xml2enc heap overflow 취약점 해결
- CVE-2026-43951 merge_response_headers OOB read crash 취약점 해결
- CVE-2026-44119 .htaccess 표현식 권한 상승 취약점 해결
- CVE-2026-44185 mod_ssl OCSP buffer over-read 취약점 해결
- CVE-2026-44186 mod_proxy_ftp infinite loop 취약점 해결
- CVE-2026-44631 ap_regname heap underflow 취약점 해결
- CVE-2026-48913 mod_http2 use-after-free 취약점 해결
- CVE-2026-49975 mod_http2 DoS 취약점 해결
- CVE-2026-23918 HTTP/2 double free 및 RCE 가능 취약점 해결
- CVE-2026-24072 mod_rewrite ap_expr 권한 상승 취약점 해결
- CVE-2026-28780 mod_proxy_ajp heap buffer overflow 취약점 해결
- CVE-2026-29168 mod_md OCSP 응답 리소스 제한 누락 취약점 해결
- CVE-2026-29169 mod_dav_lock NULL pointer dereference 취약점 해결
- CVE-2026-33006 mod_auth_digest timing attack 취약점 해결
- CVE-2026-33007 mod_authn_socache crash 취약점 해결
- CVE-2026-33523 다중 모듈 HTTP response splitting 취약점 해결
- CVE-2026-33857 mod_proxy_ajp off-by-one OOB read 취약점 해결
- CVE-2026-34032 mod_proxy_ajp null-termination 누락 OOB read 취약점 해결
- CVE-2026-34059 mod_proxy_ajp heap over-read 및 메모리 노출 취약점 해결
(WEB-N)
- CVE-2026-27654 ngx_http_dav_module buffer overflow 취약점 해결
- CVE-2026-27784 ngx_http_mp4_module buffer overflow 취약점 해결
- CVE-2026-32647 ngx_http_mp4_module buffer overflow 취약점 해결
- CVE-2026-27651 CRAM-MD5/APOP 사용 시 NULL pointer dereference 취약점 해결
- CVE-2026-28753 auth_http 및 XCLIENT injection 취약점 해결
- CVE-2026-28755 stream OCSP result bypass 취약점 해결
- CVE-2026-42926 ngx_http_proxy_module HTTP/2 request injection 취약점 해결
- CVE-2026-42945 ngx_http_rewrite_module buffer overflow 취약점 해결
- CVE-2026-42946 ngx_http_scgi/uwsgi_module buffer overread 취약점 해결
- CVE-2026-42934 ngx_http_charset_module buffer overread 취약점 해결
- CVE-2026-40460 HTTP/3 address spoofing 취약점 해결
- CVE-2026-40701 OCSP resolver use-after-free 취약점 해결
- CVE-2026-9256 ngx_http_rewrite_module buffer overflow 취약점 해결
- CVE-2026-42055 ngx_http_proxy_v2/grpc_module buffer overflow 취약점 해결
- CVE-2026-48142 ngx_http_charset_module buffer overread 취약점 해결
- CVE-2026-42530 HTTP/3 use-after-free 취약점 해결
Web Application Server
- CVE-2026-32990 SNI/호스트명 대소문자 검증 우회 취약점 해결
- CVE-2026-29146 EncryptInterceptor CBC padding oracle 취약점 해결
- CVE-2026-29145 CLIENT_CERT OCSP soft-fail 검증 오류 취약점 해결
- CVE-2026-29129 TLS cipher suite 우선순위 미보존 취약점 해결
- CVE-2026-25854 LoadBalancerDrainingValve open redirect 취약점 해결
- CVE-2026-24880 HTTP/1.1 chunk extension request smuggling 취약점 해결
- CVE-2026-34500 FFM 기반 OCSP soft-fail 검증 오류 취약점 해결
- CVE-2026-34487 Kubernetes bearer token 로그 노출 취약점 해결
- CVE-2026-34486 EncryptInterceptor 우회 취약점 해결
- CVE-2026-34483 JSON access log 주입 가능성 취약점 해결
- CVE-2026-43515 보안 제약 조건 적용 오류 취약점 해결
- CVE-2026-43514 AJP secret timing attack 취약점 해결
- CVE-2026-43513 LockOutRealm brute-force 방어 약화 취약점 해결
- CVE-2026-43512 DIGEST 인증 우회 취약점 해결
- CVE-2026-42498 WebSocket 인증 헤더 노출 취약점 해결
- CVE-2026-41293 HTTP/2 헤더 검증 누락 취약점 해결
- CVE-2026-41284 WebDAV 무제한 read 가능성 취약점 해결