SCIENTIFIC-LINUX-ERRATA Archives

October 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 24 Oct 2011 12:49:33 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (54 lines)
Synopsis:    Moderate: httpd security and bug fix update
Issue Date:  2011-10-20
CVE Numbers: CVE-2011-3348
             CVE-2011-3368


The Apache HTTP Server is a popular web server.

It was discovered that the Apache HTTP Server did not properly validate the
request URI for proxied requests. In certain configurations, if a reverse
proxy used the ProxyPassMatch directive, or if it used the RewriteRule
directive with the proxy flag, a remote attacker could make the proxy
connect to an arbitrary server, possibly disclosing sensitive information
from internal web servers not directly accessible to the attacker.
(CVE-2011-3368)

It was discovered that mod_proxy_ajp incorrectly returned an "Internal
Server Error" response when processing certain malformed HTTP requests,
which caused the back-end server to be marked as failed in configurations
where mod_proxy was used in load balancer mode. A remote attacker could
cause mod_proxy to not send requests to back-end AJP (Apache JServ
Protocol) servers for the retry timeout period or until all back-end
servers were marked as failed. (CVE-2011-3348)

This update also fixes the following bug:

* The fix for CVE-2011-3192 provided by a previous update
introduced regressions in the way httpd handled certain Range HTTP header
values. This update corrects those regressions.

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.

SL6:
  i386
     httpd-2.2.15-9.sl6.3.i686.rpm
     httpd-debuginfo-2.2.15-9.sl6.3.i686.rpm
     httpd-devel-2.2.15-9.sl6.3.i686.rpm
     httpd-tools-2.2.15-9.sl6.3.i686.rpm
     mod_ssl-2.2.15-9.sl6.3.i686.rpm
  noarch
     httpd-manual-2.2.15-9.sl6.3.noarch.rpm
  x86_64
     httpd-2.2.15-9.sl6.3.x86_64.rpm
     httpd-debuginfo-2.2.15-9.sl6.3.i686.rpm
     httpd-debuginfo-2.2.15-9.sl6.3.x86_64.rpm
     httpd-devel-2.2.15-9.sl6.3.i686.rpm
     httpd-devel-2.2.15-9.sl6.3.x86_64.rpm
     httpd-tools-2.2.15-9.sl6.3.x86_64.rpm
     mod_ssl-2.2.15-9.sl6.3.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2