Re: Apache HTTP Server Chunk Encoding Vulnerability
marcus <[email protected]> Thu, 20 Jun 2002 20:52:19 +0100 (BST)
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <[email protected]> |
Raynard, All versions of the Apache web server up to and including 1.3.24 are affected. Check out the official Apache advisory at: http://httpd.apache.org/info/security_bulletin_20020617.txt to see it for yourself. Get the Red Hat patch for Stronghold 3.0 from: http://stronghold.redhat.com/sh3/errata-2002-118 and apply the patch to Stronghold 2.4.2 by hand yourself. I guess that's the only way since Stronghold 2.4.2 is no longer supported. Else upgrade to the latest version of Stronghold. Marcus --- "Raynard A. Jong" <[email protected]> wrote: > Are older versions of Stronghold also affected by > the Apache > vulnerability recently announced by CIAC? > > PROBLEM: The Apache HTTP Server has a software > flaw that misinterprets > invalid requests encoded using > chunked encoding. This error can > be triggered remotely by sending > certain invalid requests. > PLATFORM: Any systems running Apache web server > 1.3.24 and 2.0 up to and > including 2.0.36. > DAMAGE: Successful exploitation may lead to > modified Web content, > denial of service, or further > compromise. > SOLUTION: Users of Apache 1.3 should upgrade to > 1.3.26, and users of > Apache 2.0 should upgrade to 2.0.39, > which contains a fix for > this issue. > > > In particular, is the older version, Stronghold > 2.4.2 which is built > on Apache 1.3.6 vulnerable? I notice that Apache > 1.3.6 is earlier > than the versions of Apache cited in the CIAC > bulletin. So perhaps > the older software is safe from the problem? > > If Stronghold 2.4.2 is a problem, what fixes, if > any are available? __________________________________________________ Do You Yahoo!? Everything you'll ever need on one web page from News and Sport to Email and Music Charts http://uk.my.yahoo.com