Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA 144-1 Severe: Wwwoffle Input Handling Crash Issue

debian
Calendar Grey August 6, 2002
Debian Logo
Explore the Debian security announcement released on August 6, which discusses vulnerabilities associated with input handling within the wwwoffle proxy service.
The web proxy didn'thandle input data with negative Content-Length settings properly whichcauses the processing child to crash.

Summary

A problem with wwwoffle has been discovered. The web proxy didn't
handle input data with negative Content-Length settings properly which
causes the processing child to crash. It is at this time not obvious
how this can lead to an exploitable vulnerability; however, it's better
to be safe than sorry, so here's an update.

Additionally, in the woody version empty passwords will be treated as
wrong when trying to authenticate. In the woody version we also
replaced CanonicaliseHost() with the latest routine from 2.7d, offered
by upstream. This stops bad IPv6 format IP addresses in URLs from
causing problems (memory overwriting, potential exploits).

This problem has been fixed in version 2.5c-10.4 for the old stable
distribution (potato), in version 2.7a-1.2 for the current stable
distribution (woody) and in version 2.7d-1 for the unstable
distribution (sid).

We recommend that you upgrade your wwwoffle packages.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced ...

Read the Full Advisory

Package: wwwoffle

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here