New httpd packages are available for Slackware 12.0, 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix accidental ABI breakage caused by httpd-2.2.18. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] httpd (SSA:2011-145-02) New httpd packages are available for Slackware 12.0, 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix accidental ABI breakage caused by httpd-2.2.18. Here are the details from the Slackware 13.37 ChangeLog: +--------------------------+ patches/packages/httpd-2.2.19-i486-1_slack13.37.txz: Upgraded. Revert ABI breakage in 2.2.18 caused by the function signature change of ap_unescape_url_keep2f(). This release restores the signature from 2.2.17 and prior, and introduces ap_unescape_url_keep2f_ex(). Apache httpd-2.2.18 is considered abandoned. All users must upgrade. +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 12.0: Updated package for Slackware 12.1: Updated package for Slackware 12.2: Updated package for Slackware 13.0: Updated package for Slackware x86_64 13.0: Updated package for Slackware 13.1: Updated package for Slackware 13.37: Updated package for Slackware x86_64 13.1: Updated package for Slackware x86_64 13.37: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 12.0 package: 390545a63786ce48dabac271307d8e91 httpd-2.2.19-i486-1_slack12.0.tgz Slackware 12.1 package: 9a033f2c378816cec179947b26a43b3b httpd-2.2.19-i486-1_slack12.1.tgz Slackware 12.2 package: dc503a2e86da7e2ebe88620f49318d07 httpd-2.2.19-i486-1_slack12.2.tgz Slackware 13.0 package: 0605d648aedc564607cbfa619a4d5648 httpd-2.2.19-i486-1_slack13.0.txz Slackware x86_64 13.0 package: 24badd3802df48e4f153f52be1b9f4d4 httpd-2.2.19-x86_64-1_slack13.0.txz Slackware 13.1 package: 1a5c7e9a1c4de170d0876f0517d7eff0 httpd-2.2.19-i486-1_slack13.1.txz Slackware 13.37 package: 11e0bf5494eb823aebe589a2de854efa httpd-2.2.19-i486-1_slack13.37.txz Slackware x86_64 13.1 package: 84ccfe6186280cb11e2e0e0cfb170d57 httpd-2.2.19-x86_64-1_slack13.1.txz Slackware x86_64 13.37 package: 48f826cc13c187a08ddb3491706b671d httpd-2.2.19-x86_64-1_slack13.37.txz Slackware -current package: ab8137394f625633ba756b4d43a2d7b1 n/httpd-2.2.19-i486-1.txz Slackware x86_64 -current package: ade8d482a468d3d58e41fd98b093f7b2 n/httpd-2.2.19-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg httpd-2.2.19-i486-1_slack13.37.txz Then, restart Apache httpd: # /etc/rc.d/rc.httpd stop # /etc/rc.d/rc.httpd start +-----+ . Uncover recent httpd package enhancements that tackle ABI inconsistencies in Slackware setups, bolstering security measures.. Slackware Update, Httpd Security, Apache Package Upgrade. . Severity: Important. LinuxSecurity.com Team
Several security problems have been found in the Apache web server software. It is recommended that all users of Apache upgrade to the latest stable release to fix these problems.. Several security problems have been found in the Apache web server software. It is recommended that all users of Apache upgrade to the latest stable release to fix these problems. Apache is included in our N software series in the apache.tgz package. A new apache.tgz package including Apache 1.3.14 is available in the Slackware -current tree. All users of Slackware 7.0, 7.1, and -current are urged to upgraded to this package. ========================================apache 1.3.14 AVAILABLE - (n1/apache.tgz) ======================================== The following security problems have been fixed with the release of Apache 1.3.14: * A problem with the Rewrite module, mod_rewrite, allowed access to any file on the web server under certain circumstances. * The handling of Host: headers in mass virtual hosting configurations, mod_vhost_alias, could allow access to any file on the server. * If a cgi-bin directory is under the document root, the source to the scripts inside it could be sent if using mass virtual hosting. The new Slackware apache.tgz package can be downloaded from the -current branch: This package is *ONLY* for users of Slackware 7.0 and higher. All users of Slackware 7.0 and higher that use Apache are urged to upgrade to this new package. For verification purposes, we provide the following checksums: 16-bit "sum" checksum: 36187 2184 n1/apache.tgz 128-bit MD5 message digest: 42cabff64514457bf9e81e55decda9fe n1/apache.tgz Installation instructions for the apache.tgz package: Make sure Apache is not running: # /var/lib/apache/sbin/apachectl stop Upgrade the package: # upgradepkg apache.tgz Restart Apache: # /etc/rc.d/rc.httpd You should definitelybackup your Apache configuration files and data, as upgrading this package will overwrite them with the defaults in the package. - Slackware Linux Security Team The Slackware Linux Project . Mitigate weaknesses within the Apache web server through the latest Slackware update to enhance protective measures.. apache update, Slackware security, web server patch, software upgrade. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.