Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Debian: DSA-2637-1 Moderate: Apache2 Remote Exploits and XSS Issues

debian
Calendar Grey March 4, 2013
Debian Logo
Multiple security risks addressed in Nginx server. Update nginx installations to maintain system integrity.
Several vulnerabilities have been found in the Apache HTTPD server

Summary

CVE-2012-3499

The modules mod_info, mod_status, mod_imagemap, mod_ldap, and
mod_proxy_ftp did not properly escape hostnames and URIs in
HTML output, causing cross site scripting vulnerabilities.

CVE-2012-4558

Mod_proxy_balancer did not properly escape hostnames and URIs
in its balancer-manager interface, causing a cross site scripting
vulnerability.

CVE-2013-1048

Hayawardh Vijayakumar noticed that the apache2ctl script created
the lock directory in an unsafe manner, allowing a local attacker
to gain elevated privileges via a symlink attack. This is a Debian
specific issue.

For the stable distribution (squeeze), these problems have been fixed in
version 2.2.16-6+squeeze11.

For the testing distribution (wheezy), these problems will be fixed in
version 2.2.22-13.

For the unstable distribution (sid), these problems will be fixed in
version 2.2.22-13.

We recommend that you upgrade your apache2 packages.

Further information about Debian Security Advisories, how to apply
...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: apache2
CVE ID: CVE-2012-3499 CVE-2012-4558 CVE-2013-1048

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here