Nitro Bodhisattva
Joined: 08 Apr 2002 Posts: 661 Location: San Francisco
|
Posted: Wed Jun 26, 2002 7:41 pm Post subject: [gentoo-announce] GLSA: Apache |
|
|
Seemant Kulleen wrote: | - -----------------------------------------------------------------------
GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
- -----------------------------------------------------------------------
PACKAGE : Apache
SUMMARY : security vulnerability in apache
DATE : Wed Jun 19 18:55:49 UTC 2002
- -----------------------------------------------------------------------
OVERVIEW
An exploit in the handling of 'Chunked Encoding' can lead to DoS or
possibly execution of arbitrary code. Functionality is enabled by default.
DETAIL
Most cases are caught as invalid requests and simply consume child
processes. Only outcome is DoS (by child throttling) in those cases.
http://httpd.apache.org/info/security_bulletin_20020617.txt
SOLUTION
It is recommended that all Gentoo Linux users who are running apache
update their systems as follows.
emerge --clean rsync
emerge apache
emerge clean |
Mailing list archive: http://lists.gentoo.org/pipermail/gentoo-announce/2002-June/000165.html _________________ - Kyle Manna
Please, please SEARCH before posting.
There are three kinds of people in the world: those who can count, and those who can't. |
|