Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Slackware: 2023-153-02 Moderate: Patch for Nginx Service Disruption Risk

slackware
Calendar Grey May 12, 2004
Dist Slackware Esm H88
Updated apache packages for Slackware address vulnerabilities associated with denial-of-service exploits and command injection risks.
New apache packages are available for Slackware 8.1, 9.0, 9.1, and -current to fix security issues

Summary

Here are the details from the Slackware 9.1 ChangeLog: Wed May 12 13:06:39 PDT 2004 patches/packages/apache-1.3.29-i486-2.tgz: Patched four security issues in the Apache web server as noted on https://httpd.apache.org/. These security fixes were backported from Apache 1.3.31: In mod_digest, verify whether the nonce returned in the client response is one we issued ourselves. This problem does not affect mod_auth_digest. (CAN-2003-0987) Escape arbitrary data before writing into the errorlog. (CAN-2003-0020) Fix starvation issue on listening sockets where a short-lived connection on a rarely-accessed listening socket will cause a child to hold the accept mutex and block out new connections until another connection arrives on that rarely-accessed listening socket. (CAN-2004-0174) Fix parsing of Allow/Deny rules using IP addresses without a netmask; issue is only known to affect big-endian 64-bit platforms (CAN-2003-0993) For more

Read the Full Advisory

Where Find New Packages

Updated package for Slackware 8.1:
Updated package for Slackware 9.0:
Updated package for Slackware 9.1:
Updated packages for Slackware -current: (these related packages are also available)

MD5 Signatures

Slackware 8.1 package: 53949a74ba3dd0a01271e3aa1178e082 apache-1.3.29-i386-2.tgz
Slackware 9.0 package: 64ede1f5637736842502301eb5bd727d apache-1.3.29-i386-2.tgz
Slackware 9.1 package: ec5dad948d8b17b82b91d756a5c6b0f9 apache-1.3.29-i486-2.tgz
Slackware -current packages: a925f8be7b8bbcb7e4a77e2ef755988a apache-1.3.31-i486-1.tgz 684626575e1c2a783b3d8d208876aab4 mod_ssl-2.8.17_1.3.31-i486-2.tgz ad27d5f96281e11567184411b7c0720e php-4.3.6-i486-2.tgz

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: First, stop apache: # apachectl stop Next, upgrade the Apache package as root: (if you're running -current, upgrade mod_ssl and php as well) # upgradepkg apache-1.3.29-i486-2.tgz Finally, restart apache: # apachectl start Or, if you're running a secure server with mod_ssl: # apachectl startssl

Related News

Your message here