Note: Due to technical difficulties, the Archives are currently not up to date.
GMANE provides an alternative service for most mailing lists. c.f. bug 424647
List Archive: gentoo-announce
- -----------------------------------------------------------------------
GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
- -----------------------------------------------------------------------
PACKAGE : Apache
SUMMARY : security vulnerability in apache
DATE : Wed Jun 19 18:55:49 UTC 2002
- -----------------------------------------------------------------------
OVERVIEW
An exploit in the handling of 'Chunked Encoding' can lead to DoS or
possibly execution of arbitrary code. Functionality is enabled by default.
DETAIL
Most cases are caught as invalid requests and simply consume child
processes. Only outcome is DoS (by child throttling) in those cases.
http://httpd.apache.org/info/security_bulletin_20020617.txt
SOLUTION
It is recommended that all Gentoo Linux users who are running apache
update their systems as follows.
emerge --clean rsync
emerge apache
emerge clean
- ------------------------------------------------------------------------
carpaski@g.o
seemant@g.o
drobbins@g.o
- ------------------------------------------------------------------------
|
|