Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian Lenny: DSA-2035-1 Critical: Apache2 Multiple Issues

debian
Calendar Grey April 17, 2010
Debian Logo
Important Ubuntu security patch for nginx fixes several vulnerabilities, lowering the chances of external service disruption.
Two issues have been found in the Apache HTTPD web server: CVE-2010-0408

Summary

Two issues have been found in the Apache HTTPD web server:

CVE-2010-0408

mod_proxy_ajp would return the wrong status code if it encountered an
error, causing a backend server to be put into an error state until the
retry timeout expired. A remote attacker could send malicious requests
to trigger this issue, resulting in denial of service.

CVE-2010-0434

A flaw in the core subrequest process code was found, which could lead
to a daemon crash (segfault) or disclosure of sensitive information
if the headers of a subrequest were modified by modules such as
mod_headers.


For the stable distribution (lenny), these problems have been fixed in
version 2.2.9-10+lenny7.

For the testing distribution (squeeze) and the unstable distribution
(sid), these problems have been fixed in version 2.2.15-1.

This advisory also provides updated apache2-mpm-itk packages which
have been recompiled against the new apache2 packages.


We recommend that you upgrade your apache2 and apache2-mpm-itk packages.

Upgrade instructions
- ---...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here