Subject: | |
From: | |
Reply To: | |
Date: | Wed, 12 Nov 2008 12:30:42 -0600 |
Content-Type: | text/plain |
Parts/Attachments: |
|
|
Synopsis: Moderate: httpd security and bug fix update
Issue date: 2008-11-11
CVE Names: CVE-2008-2364 CVE-2008-2939
A flaw was found in the mod_proxy Apache module. An attacker in control of
a Web server to which requests were being proxied could have caused a
limited denial of service due to CPU consumption and stack exhaustion.
(CVE-2008-2364)
A flaw was found in the mod_proxy_ftp Apache module. If Apache was
configured to support FTP-over-HTTP proxying, a remote attacker could have
performed a cross-site scripting attack. (CVE-2008-2939)
In addition, these updated packages fix a bug found in the handling of the
"ProxyRemoteMatch" directive in the Scientific Linux 4 httpd
packages. This bug is not present in the Scientific Linux 3 or
Scientific Linux 5 packages.
SL 3.0.x
SRPMS:
httpd-2.0.46-71.sl3.src.rpm
i386:
httpd-2.0.46-71.sl3.i386.rpm
httpd-devel-2.0.46-71.sl3.i386.rpm
mod_ssl-2.0.46-71.sl3.i386.rpm
x86_64:
httpd-2.0.46-71.sl3.x86_64.rpm
httpd-devel-2.0.46-71.sl3.x86_64.rpm
mod_ssl-2.0.46-71.sl3.x86_64.rpm
SL 4.x
SRPMS:
httpd-2.0.52-41.sl4.2.src.rpm
i386:
httpd-2.0.52-41.sl4.2.i386.rpm
httpd-devel-2.0.52-41.sl4.2.i386.rpm
httpd-manual-2.0.52-41.sl4.2.i386.rpm
httpd-suexec-2.0.52-41.sl4.2.i386.rpm
mod_ssl-2.0.52-41.sl4.2.i386.rpm
x86_64:
httpd-2.0.52-41.sl4.2.x86_64.rpm
httpd-devel-2.0.52-41.sl4.2.x86_64.rpm
httpd-manual-2.0.52-41.sl4.2.x86_64.rpm
httpd-suexec-2.0.52-41.sl4.2.x86_64.rpm
mod_ssl-2.0.52-41.sl4.2.x86_64.rpm
SL 5.x
SRPMS:
httpd-2.2.3-11.sl5.4.src.rpm
i386:
httpd-2.2.3-11.sl5.4.i386.rpm
httpd-devel-2.2.3-11.sl5.4.i386.rpm
httpd-manual-2.2.3-11.sl5.4.i386.rpm
mod_ssl-2.2.3-11.sl5.4.i386.rpm
x86_64:
httpd-2.2.3-11.sl5.4.x86_64.rpm
httpd-devel-2.2.3-11.sl5.4.i386.rpm
httpd-devel-2.2.3-11.sl5.4.x86_64.rpm
httpd-manual-2.2.3-11.sl5.4.x86_64.rpm
mod_ssl-2.2.3-11.sl5.4.x86_64.rpm
-Connie Sieh
-Troy Dawson
|
|
|