Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Debian: DSA-2298-2 Moderate: Apache2 DoS Regression Fix

debian
Calendar Grey September 5, 2011
Debian Logo
The Debian Security Advisory DSA-2298-2 addresses a regression in apache2 that impacts video streaming; users are urged to upgrade.
The apache2 Upgrade from DSA-2298-1 has caused a regression that prevented some video players from seeking in video files served by Apache HTTPD

Summary


The text of the original advisory is reproduced for reference:

Two issues have been found in the Apache HTTPD web server:

CVE-2011-3192

A vulnerability has been found in the way the multiple overlapping
ranges are handled by the Apache HTTPD server. This vulnerability
allows an attacker to cause Apache HTTPD to use an excessive amount of
memory, causing a denial of service.

CVE-2010-1452

A vulnerability has been found in mod_dav that allows an attacker to
cause a daemon crash, causing a denial of service. This issue only
affects the Debian 5.0 oldstable/lenny distribution.


The regression has been fixed in the following packages:

For the oldstable distribution (lenny), this problem has been fixed
in version 2.2.9-10+lenny11.

For the stable distribution (squeeze), this problem has been fixed in
version 2.2.16-6+squeeze3.

For the testing distribution (wheezy), this problem will be fixed in
version 2.2.20-1.

For the unstable distribution (sid), this problem has been fixed in
version 2.2.20-1.

We recommend ...

Read the Full Advisory

Package: apache2
CVE ID: CVE-2010-1452 CVE-2011-3192

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here