Gentoo Archives: gentoo-announce

From: Seemant Kulleen <seemant@g.o>
To: gentoo-announce@g.o, lwn@×××.net
Subject: [gentoo-announce] GLSA: Apache
Date: Wed, 19 Jun 2002 17:31:35
Message-Id: 20020619153134.62c37891.seemant@gentoo.org
- -----------------------------------------------------------------------
GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
- -----------------------------------------------------------------------
PACKAGE         : Apache
SUMMARY         : security vulnerability in apache
DATE            : Wed Jun 19 18:55:49 UTC 2002
- -----------------------------------------------------------------------

OVERVIEW

An exploit in the handling of 'Chunked Encoding' can lead to DoS or
possibly execution of arbitrary code. Functionality is enabled by default.

DETAIL

Most cases are caught as invalid requests and simply consume child
processes. Only outcome is DoS (by child throttling) in those cases.

http://httpd.apache.org/info/security_bulletin_20020617.txt

SOLUTION

It is recommended that all Gentoo Linux users who are running apache
update their systems as follows.

emerge --clean rsync
emerge apache
emerge clean

- ------------------------------------------------------------------------
carpaski@g.o
seemant@g.o
drobbins@g.o
- ------------------------------------------------------------------------