Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian Security Advisory: DSA-2937-1 on Mod-Wsgi Vulnerability Alert

debian
Calendar Grey May 27, 2014
Debian Logo
Recent Debian updates address two critical vulnerabilities in mod-wsgi. Users are advised to perform upgrades to enhance the security and functionality of Apache servers.
Two security issues have been found in the Python WSGI adapter module for Apache: CVE-2014-0240

Summary

Two security issues have been found in the Python WSGI adapter module
for Apache:

CVE-2014-0240

Robert Kisteleki discovered a potential privilege escalation in
daemon mode. This is not exploitable with the kernel used in Debian
7.0/wheezy.

CVE-2014-0242

Buck Golemon discovered that incorect memory handling could lead to
information disclosure when processing Content-Type headers.

For the oldstable distribution (squeeze), these problems have been fixed in
version 3.3-2+deb6u1.

For the stable distribution (wheezy), these problems have been fixed in
version 3.3-4+deb7u1.

For the testing distribution (jessie), these problems have been fixed in
version 3.5-1.

For the unstable distribution (sid), these problems have been fixed in
version 3.5-1.

We recommend that you upgrade your mod-wsgi packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: mod-wsgi
CVE ID: CVE-2014-0240 CVE-2014-0242

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here