Apache HTTP Server Chunk Encoding Vulnerability

"Raynard A. Jong" <[email protected]> Thu, 20 Jun 2002 10:47:52 -0700
Newsgroups gmane.linux.redhat.stronghold
Message-ID <p05100302b937c5b1cfd2@[128.115.101.2]>
Are older versions of Stronghold also affected by the Apache 
vulnerability recently announced by CIAC?

PROBLEM:       The Apache HTTP Server has a software flaw that misinterprets
                invalid requests encoded using chunked encoding. This error can
                be triggered remotely by sending certain invalid requests.
PLATFORM:      Any systems running Apache web server 1.3.24 and 2.0 up to and
                including 2.0.36.
DAMAGE:        Successful exploitation may lead to modified Web content,
                denial of service, or further compromise.
SOLUTION:      Users of Apache 1.3 should upgrade to 1.3.26, and users of
                Apache 2.0 should upgrade to 2.0.39, which contains a fix for
                this issue.


In particular, is the older version, Stronghold 2.4.2 which is built 
on Apache 1.3.6  vulnerable?  I notice that Apache 1.3.6 is earlier 
than the versions of Apache cited in the CIAC bulletin.  So perhaps 
the older software is safe from the problem?

If Stronghold  2.4.2 is a problem, what fixes, if any are available?



_______________________________________________
Stronghold-users mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/stronghold-users