Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 12.10: USN-1765-1 Moderate: Apache2 Cross-Site Scripting DoS

ubuntu
Calendar Grey March 18, 2013
Scroller Ubuntu
Numerous vulnerabilities addressed in Apache HTTP Server across various Ubuntu versions. Secure your environment today.
Several security issues were fixed in the Apache HTTP Server.

Summary

Several security issues were fixed in the Apache HTTP Server.

Software Description:

- apache2: Apache HTTP server

Details:

Niels Heinen discovered that multiple modules incorrectly sanitized certain

strings, which could result in browsers becoming vulnerable to cross-site

scripting attacks when processing the output. With cross-site scripting

vulnerabilities, if a user were tricked into viewing server output during a

crafted server request, a remote attacker could exploit this to modify the

contents, or steal confidential data (such as passwords), within the same

domain. (CVE-2012-3499, CVE-2012-4558)

It was discovered that the mod_proxy_ajp module incorrectly handled error

states. A remote attacker could use this issue to cause the server to stop

responding, resulting in a denial of service. This issue only applied to

Ubuntu 8.04 LTS, Ubuntu 10.04 LTS and Ubuntu 11.10. (CVE-2012-4557)

It was discovered that the apache2ctl script shipped in Ubuntu packages

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  apache2.2-common                2.2.22-6ubuntu2.2

Ubuntu 12.04 LTS:
  apache2.2-common                2.2.22-1ubuntu1.3

Ubuntu 11.10:
  apache2.2-common                2.2.20-1ubuntu1.4

Ubuntu 10.04 LTS:
  apache2.2-common                2.2.14-5ubuntu8.11

Ubuntu 8.04 LTS:
  apache2.2-common                2.2.8-1ubuntu0.25

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1765-1

CVE-2012-3499, CVE-2012-4557, CVE-2012-4558, CVE-2013-1048

Severity
important
Lowest
Low
Medium
High
Critical

March 18, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.