Debian: libapache-mod-python Denial of service vulnerability

    Date01 Mar 2004
    CategoryDebian
    2241
    Posted ByLinuxSecurity Advisories
    Fixes a bug which allows a malformed query string to crash the corresponding Apache child process.
    
    Debian Security Advisory DSA 452-1                     This email address is being protected from spambots. You need JavaScript enabled to view it. 
    http://www.debian.org/security/                             Matt Zimmerman
    February 29th, 2004                      http://www.debian.org/security/faq
    - --------------------------------------------------------------------------
    
    Package        : libapache-mod-python
    Vulnerability  : denial of service
    Problem-Type   : remote
    Debian-specific: no
    CVE Id         : CAN-2003-0973
    Debian bug     : 222828
    
    The Apache Software Foundation announced that some versions of
    mod_python contain a bug which, when processing a request with a
    malformed query string, could cause the corresponding Apache child to
    crash.  This bug could be exploited by a remote attacker to cause a
    denial of service.
    
    For the current stable distribution (woody) this problem has been
    fixed in version 2:2.7.8-0.0woody2.
    
    For the unstable distribution (sid), this problem has been fixed in
    version 2:2.7.10-1.
    
    We recommend that you update your libapache-mod-python package.
    
    Upgrade Instructions
    - --------------------
    
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    
    Debian GNU/Linux 3.0 alias woody
    - --------------------------------
    
      Source archives:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2.dsc
          Size/MD5 checksum:      715 3f6bd19f154109251e7ee9b8db73ebfb
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2.diff.gz
          Size/MD5 checksum:     7564 bad7102a98f242d28ff3736e4e971fe5
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8.orig.tar.gz
          Size/MD5 checksum:   176639 4d5bee8317bfb45a3bb09f02b435e917
    
      Alpha architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_alpha.deb
          Size/MD5 checksum:   120032 20e1ba89516235ec67df12f8a0236198
    
      ARM architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_arm.deb
          Size/MD5 checksum:   117906 64b6fbcbe483dc388f5cb4e75fa63610
    
      Intel IA-32 architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_i386.deb
          Size/MD5 checksum:   117296 e2ab69380e7e9451ab454605cb1d3e34
    
      Intel IA-64 architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_ia64.deb
          Size/MD5 checksum:   131076 cea1f9dca578ba7e4cac7a7bc8638829
    
      HP Precision architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_hppa.deb
          Size/MD5 checksum:   119784 fcfe4d4ddbdbf29255a51eee77c10422
    
      Motorola 680x0 architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_m68k.deb
          Size/MD5 checksum:   118270 dff9473d327a981959831c9a08a48053
    
      Big endian MIPS architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_mips.deb
          Size/MD5 checksum:   117288 0d51ab71f85b5d93b23f593be4e8e7e6
    
      Little endian MIPS architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_mipsel.deb
          Size/MD5 checksum:   117018 52d9bca3ae178e68ef20b64dfb6b96a9
    
      PowerPC architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_powerpc.deb
          Size/MD5 checksum:   118232 6a42f9f8f923837788b586c711a6fa6b
    
      IBM S/390 architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_s390.deb
          Size/MD5 checksum:   119002 f13e42b816e93b5c6533df6b8c0aa597
    
      Sun Sparc architecture:
    
         http://security.debian.org/pool/updates/main/liba/libapache-mod-python/libapache-mod-python_2.7.8-0.0woody2_sparc.deb
          Size/MD5 checksum:   118176 23da855358f4b8cff799a9478c8e2d81
    
      These files will probably be moved into the stable distribution on
      its next revision.
    
    - ---------------------------------------------------------------------------------
    For apt-get: deb  http://security.debian.org/ stable/updates main
    For dpkg-ftp:  ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it.
    Package info: `apt-cache show ' and  http://packages.debian.org/
    
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"65","type":"x","order":"1","pct":57.52,"resources":[]},{"id":"88","title":"Should be more technical","votes":"15","type":"x","order":"2","pct":13.27,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"33","type":"x","order":"3","pct":29.2,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.