Apache HTTP Server Chunk Encoding Vulnerability

"Raynard A. Jong" <[email protected]> Wed, 19 Jun 2002 17:52:18 -0700
Newsgroups gmane.linux.redhat.stronghold
Message-ID <p05100303b936d5c67187@[128.115.101.2]>
Are versions of Stronghold also affected by the Apache vulnerability 
recently announced by CIAC?

PROBLEM:       The Apache HTTP Server has a software flaw that misinterprets
                invalid requests encoded using chunked encoding. This error can
                be triggered remotely by sending certain invalid requests.
PLATFORM:      Any systems running Apache web server 1.3.24 and 2.0 up to and
                including 2.0.36.
DAMAGE:        Successful exploitation may lead to modified Web content,
                denial of service, or further compromise.
SOLUTION:      Users of Apache 1.3 should upgrade to 1.3.26, and users of
                Apache 2.0 should upgrade to 2.0.39, which contains a fix for
                this issue.


In particular, is the older version, Stronghold 2.4.2 which is built 
on Apache 1.3.6  vulnerable?  I notice that Apache 1.3.6 is earlier 
than the versions of Apache cited in the CIAC bulletin.  So perhaps 
the older software is safe from the problem?

If Stronghold  2.4.2 is a problem, what fixes, if any are available?