klieber Bodhisattva
Joined: 17 Apr 2002 Posts: 3657 Location: San Francisco, CA
|
Posted: Tue Nov 12, 2002 4:53 pm Post subject: [gentoo-announce] GLSA: apache |
|
|
Daniel Ahlberg wrote: | - - -------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200211-003
- - --------------------------------------------------------------------
PACKAGE : apache
SUMMARY: Cross-Site Scripting Vulnerability
DATE : 2002-11-12 14:11 UTC
EXPLOIT : local
- - --------------------------------------------------------------------
A vulnerability exists in the SSI error pages of Apache 2.0 that involves incorrect filtering of server signature data. The vulnerability could enable an attacker to hijack web sessions, allowing a range of potential compromises on the targeted host.
Read the full advisory at
http://online.securityfocus.com/archive/1/293791
SOLUTION
It is recommended that all Gentoo Linux users who are running net-www/apache-2.0.42 and earlier update their systems as follows:
emerge rsync
emerge apache
emerge clean
- - --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
- - -------------------------------------------------------------------- |
Mailing List Archive: unavailable
--kurt _________________ The problem with political jokes is that they get elected |
|