Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Ubuntu 11.04 LTS USN-1259-1 Severe: Apache Denial of Service

ubuntu
Calendar Grey November 11, 2011
Scroller Ubuntu
Numerous security flaws in Apache addressed with patches for different iterations of Ubuntu, enhancing both safety and performance.
Multiple vulnerabilities and a regression were fixed in the Apache HTTPserver.

Summary

Multiple vulnerabilities and a regression were fixed in the Apache HTTP

server.

Software Description:

- apache2: Apache HTTP server

- apache2-mpm-itk: multiuser MPM for Apache 2.2

Details:

It was discovered that the mod_proxy module in Apache did not properly

interact with the RewriteRule and ProxyPassMatch pattern matches

in the configuration of a reverse proxy. This could allow remote

attackers to contact internal webservers behind the proxy that were

not intended for external exposure. (CVE-2011-3368)

Stefano Nichele discovered that the mod_proxy_ajp module in Apache when

used with mod_proxy_balancer in certain configurations could allow

remote attackers to cause a denial of service via a malformed HTTP

request. (CVE-2011-3348)

Samuel Montosa discovered that the ITK Multi-Processing Module for

Apache did not properly handle certain configuration sections that

specify NiceValue but not AssignUserID, preventing Apache from dropping

privileges correctly. This issue only affect...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  apache2.2-bin                   2.2.20-1ubuntu1.1

Ubuntu 11.04:
  apache2-mpm-itk                 2.2.17-1ubuntu1.4
  apache2.2-bin                   2.2.17-1ubuntu1.4

Ubuntu 10.10:
  apache2-mpm-itk                 2.2.16-1ubuntu3.4
  apache2.2-bin                   2.2.16-1ubuntu3.4

Ubuntu 10.04 LTS:
  apache2-mpm-itk                 2.2.14-5ubuntu8.7
  apache2.2-bin                   2.2.14-5ubuntu8.7

Ubuntu 8.04 LTS:
  apache2.2-common                2.2.8-1ubuntu0.22

In general, a standard system update will make all the necessary changes.

References

CVE-2011-1176, CVE-2011-3348, CVE-2011-3368

Severity
critical
Lowest
Low
Medium
High
Critical

November 11, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.