Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA-532-1 Critical: libapache-mod-ssl Remote Code Execution Risk

debian
Calendar Grey July 23, 2004
Debian Logo
Enhance libapache-mod-ssl to address potential remote code execution flaws arising from buffer overflow and format string issues.
This patch resolves a buffer overflow and a format string vulnerability, either of which can lead to an arbitrary code execution.

Summary

Two vulnerabilities were discovered in libapache-mod-ssl:

CAN-2004-0488 - Stack-based buffer overflow in the
ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl,
when mod_ssl is configured to trust the issuing CA, may allow remote
attackers to execute arbitrary code via a client certificate with a
long subject DN.

CAN-2004-0700 - Format string vulnerability in the ssl_log function
in ssl_engine_log.c in mod_ssl 2.8.19 for Apache 1.3.31 may allow
remote attackers to execute arbitrary messages via format string
specifiers in certain log messages for HTTPS.

For the current stable distribution (woody), these problems have been
fixed in version 2.8.9-2.3.

For the unstable distribution (sid), CAN-2004-0488 was fixed in
version 2.8.18, and CAN-2004-0700 will be fixed soon.

We recommend that you update your libapache-mod-ssl package.

Upgrade Instructions
- --------------------

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: libapache-mod-ssl

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here