SCIENTIFIC-LINUX-ERRATA Archives

October 2011

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 24 Oct 2011 14:50:20 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (58 lines)
Synopsis:    Moderate: httpd security and bug fix update
Issue Date:  2011-10-20
CVE Numbers: CVE-2011-3368


The Apache HTTP Server is a popular web server.

It was discovered that the Apache HTTP Server did not properly validate the
request URI for proxied requests. In certain configurations, if a reverse
proxy used the ProxyPassMatch directive, or if it used the RewriteRule
directive with the proxy flag, a remote attacker could make the proxy
connect to an arbitrary server, possibly disclosing sensitive information
from internal web servers not directly accessible to the attacker.
(CVE-2011-3368)

This update also fixes the following bug:

* The fix for CVE-2011-3192 provided by a previous update
introduced regressions in the way httpd handled certain Range HTTP header
values. This update corrects those regressions.

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.

SL4:
  i386
     httpd-2.0.52-49.sl4.i386.rpm
     httpd-debuginfo-2.0.52-49.sl4.i386.rpm
     httpd-devel-2.0.52-49.sl4.i386.rpm
     httpd-manual-2.0.52-49.sl4.i386.rpm
     httpd-suexec-2.0.52-49.sl4.i386.rpm
     mod_ssl-2.0.52-49.sl4.i386.rpm
  x86_64
     httpd-2.0.52-49.sl4.x86_64.rpm
     httpd-debuginfo-2.0.52-49.sl4.x86_64.rpm
     httpd-devel-2.0.52-49.sl4.x86_64.rpm
     httpd-manual-2.0.52-49.sl4.x86_64.rpm
     httpd-suexec-2.0.52-49.sl4.x86_64.rpm
     mod_ssl-2.0.52-49.sl4.x86_64.rpm
SL5:
  i386
     httpd-2.2.3-53.sl5.3.i386.rpm
     httpd-debuginfo-2.2.3-53.sl5.3.i386.rpm
     httpd-devel-2.2.3-53.sl5.3.i386.rpm
     httpd-manual-2.2.3-53.sl5.3.i386.rpm
     mod_ssl-2.2.3-53.sl5.3.i386.rpm
  x86_64
     httpd-2.2.3-53.sl5.3.x86_64.rpm
     httpd-debuginfo-2.2.3-53.sl5.3.i386.rpm
     httpd-debuginfo-2.2.3-53.sl5.3.x86_64.rpm
     httpd-devel-2.2.3-53.sl5.3.i386.rpm
     httpd-devel-2.2.3-53.sl5.3.x86_64.rpm
     httpd-manual-2.2.3-53.sl5.3.x86_64.rpm
     mod_ssl-2.2.3-53.sl5.3.x86_64.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2