Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA 188-1 Critical: Apache-SSL Denial of Service and XSS

debian
Calendar Grey November 5, 2002
Debian Logo
The important notification DSA-200-2 from Ubuntu highlights urgent fixes for nginx vulnerabilities, particularly those that could result in potential information leaks.
There are vulnerabilities that could allow an attacker to enact a denial of service against a server or execute a cross scripting attack, or steal cookies from other web site users

Summary

According to David Wagner, iDEFENSE and the Apache HTTP Server
Project, several vulnerabilities have been found in the Apache
package, a commonly used webserver. Most of the code is shared
between the Apache and Apache-SSL packages, so vulnerabilities are
shared as well. These vulnerabilities could allow an attacker to
enact a denial of service against a server or execute a cross
scripting attack, or steal cookies from other web site users.
Vulnerabilities in the included lecacy programs htdigest, htpasswd and
ApacheBench can be exploited when called via CGI. Additionally the
insecure temporary file creation in htdigest and htpasswd can also be
exploited locally. The Common Vulnerabilities and Exposures (CVE)
project identified the following vulnerabilities:

1. CAN-2002-0839: A vulnerability exists on platforms using System V
shared memory based scoreboards. This vulnerability allows an
attacker to execute code under the Apache UID to exploit the Apache
shared memory scoreboard forma...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: apache-ssl

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here