Re: help in patching

Mark J Cox <[email protected]> Wed, 26 Jun 2002 12:21:27 +0100 (BST)
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
> Did you actually verify that this release is vulnerable to the chunk 
> enconding problem? I have a Stronghold 3 release that WAS NO vulnerable.

All Apache releases since Apache 1.2 are vulnerable to the chunked
encoding issue, therefore so are all releases of Stronghold.  We have been
informed that the eEye tool was looking only at the returned server
version to make its assesment of vulnerability, however that is not
sufficient to find Stronghold (which changes the server version string),
or servers that are not running Apache 1.3.26 but have been patched.

[Although all releases of Stronghold are vulnerable the effects and
exploitability vary from platform to platform.  We suggest that all
Stronghold users apply the patch or upgrade to the 3017 binaries]

Cheers, Mark
--
Mark J Cox / Red Hat / OpenSSL / Apache Software Foundation
[email protected] // T: +44 798 061 3110 // F: +44 870 1319174