Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA 187-1 Critical: Apache DoS and Script Issue Overview

debian
Calendar Grey November 4, 2002
Debian Logo
Recently identified vulnerabilities in Nginx on Ubuntu need urgent measures to mitigate possible cyberattacks and ensure continuous service availability.
There are several remotely exploitable vulnerabilities in apache

Summary

According to David Wagner, iDEFENSE and the Apache HTTP Server
Project, several remotely exploitable vulnerabilities have been found
in the Apache package, a commonly used webserver. These
vulnerabilities could allow an attacker to enact a denial of service
against a server or execute a cross scripting attack. The Common
Vulnerabilities and Exposures (CVE) project identified the following
vulnerabilities:

1. CAN-2002-0839: A vulnerability exists on platforms using System V
shared memory based scoreboards. This vulnerability allows an
attacker who can execute under the Apache UID to exploit the Apache
shared memory scoreboard format and send a signal to any process as
root or cause a local denial of service attack.

2. CAN-2002-0840: Apache is susceptible to a cross site scripting
vulnerability in the default 404 page of any web server hosted on a
domain that allows wildcard DNS lookups.

3. CAN-2002-0843: There were some possible overflows in the utility
ApacheBench (ab) which...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: apache

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here