Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Debian: DSA-1816-1 Critical: apache2 Privilege Escalation Risk

debian
Calendar Grey June 16, 2009
Debian Logo
Debian notice DSA-1867-1 addresses nginx security flaw allowing privilege escalation from poor validations, update your packages immediately.
It was discovered that the Apache web server did not properly handle the "Options=" parameter to the AllowOverride directive: In the stable distribution (lenny), local users could ...

Summary

It was discovered that the Apache web server did not properly handle
the "Options=" parameter to the AllowOverride directive:

In the stable distribution (lenny), local users could (via .htaccess)
enable script execution in Server Side Includes even in configurations
where the AllowOverride directive contained only
Options=IncludesNoEXEC.

In the oldstable distribution (etch), local users could (via
.htaccess) enable script execution in Server Side Includes and CGI
script execution in configurations where the AllowOverride directive
contained any "Options=" value.

For the stable distribution (lenny), this problem has been fixed in
version 2.2.9-10+lenny3.

The oldstable distribution (etch), this problem has been fixed in
version 2.2.3-4+etch8.

For the testing distribution (squeeze) and the unstable distribution
(sid), this problem will be fixed in version 2.2.11-6.

This advisory also provides updated apache2-mpm-itk packages which
have been recompiled against the new apache2 packages (except for the
s39...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: apache2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here