Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Ubuntu 12.10: USN-1627-1 Critical Apache HTTP Server Cross-Site Scripting

ubuntu
Calendar Grey November 8, 2012
Scroller Ubuntu
Ubuntu Security Notice USN-1728-2 addresses vulnerabilities in the OpenSSH server impacting various Ubuntu versions.
Several security issues were fixed in the Apache HTTP server.

Summary

Several security issues were fixed in the Apache HTTP server.

Software Description:

- apache2: Apache HTTP server

Details:

It was discovered that the mod_negotiation module incorrectly handled

certain filenames, which could result in browsers becoming vulnerable to

cross-site scripting attacks when processing the output. With cross-site

scripting vulnerabilities, if a user were tricked into viewing server

output during a crafted server request, a remote attacker could exploit

this to modify the contents, or steal confidential data (such as

passwords), within the same domain. (CVE-2012-2687)

It was discovered that the Apache HTTP Server was vulnerable to the "CRIME"

SSL data compression attack. Although this issue had been mitigated on the

client with newer web browsers, this update also disables SSL data

compression on the server. A new SSLCompression directive for Apache has

been backported that may be used to re-enable SSL data compression in

certain envi...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  apache2.2-common                2.2.22-6ubuntu2.1

Ubuntu 12.04 LTS:
  apache2.2-common                2.2.22-1ubuntu1.2

Ubuntu 11.10:
  apache2.2-common                2.2.20-1ubuntu1.3

Ubuntu 10.04 LTS:
  apache2.2-common                2.2.14-5ubuntu8.10

Ubuntu 8.04 LTS:
  apache2.2-common                2.2.8-1ubuntu0.24

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1627-1

CVE-2012-2687, CVE-2012-4929

Severity
critical
Lowest
Low
Medium
High
Critical

November 08, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.