Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 14.04 LTS USN-2299-1 Critical: Apache HTTP Server DoS

ubuntu
Calendar Grey July 23, 2014
Scroller Ubuntu
Managing various Apache server challenges in Ubuntu, notably Denial of Service vulnerabilities. Key details enclosed.
Several security issues were fixed in Apache HTTP Server.

Summary

Several security issues were fixed in Apache HTTP Server.

Software Description:

- apache2: Apache HTTP server

Details:

Marek Kroemeke discovered that the mod_proxy module incorrectly handled

certain requests. A remote attacker could use this issue to cause the

server to stop responding, leading to a denial of service. This issue only

affected Ubuntu 14.04 LTS. (CVE-2014-0117)

Giancarlo Pellegrino and Davide Balzarotti discovered that the mod_deflate

module incorrectly handled body decompression. A remote attacker could use

this issue to cause resource consumption, leading to a denial of service.

(CVE-2014-0118)

Marek Kroemeke and others discovered that the mod_status module incorrectly

handled certain requests. A remote attacker could use this issue to cause

the server to stop responding, leading to a denial of service, or possibly

execute arbitrary code. (CVE-2014-0226)

Rainer Jung discovered that the mod_cgid module incorrectly handled certain

script...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  apache2-bin                     2.4.7-1ubuntu4.1

Ubuntu 12.04 LTS:
  apache2.2-bin                   2.2.22-1ubuntu1.7

Ubuntu 10.04 LTS:
  apache2.2-bin                   2.2.14-5ubuntu8.14

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2299-1

CVE-2014-0117, CVE-2014-0118, CVE-2014-0226, CVE-2014-0231

Severity
critical
Lowest
Low
Medium
High
Critical

July 23, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.