Re: FW: CERT Advisory CA-2002-17 Apache Web Server Chunk Handling Vulnerability

Min Min <[email protected]> Thu, 20 Jun 2002 13:50:47 +0100 (BST)
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
Hello Craig,

> Is this an issue with stronghold? If so what versions are affected? Is
> there a patch available?

Yes, this is an issue with all versions of Stronghold 3.0 as it is based
on Apache 1.3.

The chunk size vulnerability patch for Stronghold 3 build 3016 is now
available at:

http://stronghold.redhat.com/sh3/errata-2002-118.xml

Before applying the patch, please ensure that you can recompile Stronghold
on its own successfully by:

1. Change to the src directory in the Stronghold installation root:
# cd <ServerRoot>/src 

2. Configure and build Stronghold:
# ./Configure
# make 

Once you have ensured the you can recompile Stronghold successfully on its
own, then you may follow the steps on the page to apply the patch. If you
are using an older version of Stronghold 3.0, when you apply the patch,
you will get some rejects. Just apply the rejected code manually by hand
to the http_protocol.c source code where possible and recompile
Stronghold.

The patch for Stronghold 4 is at:

http://stronghold.redhat.com/sh4/errata-2002-118 

Stronghold 3.0 build code 3017 that is not vulnerable to this issue will
soon be available from:

http://stronghold.redhat.com/olddownloads.xml

by end of next week.

Hope this helps! If we can be of assistance in any way, please do not
hesitate to contact us.

Best regards,
Min Min