Re: help in patching
Mark J Cox <[email protected]> Wed, 26 Jun 2002 12:21:27 +0100 (BST)
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <[email protected]> |
> Did you actually verify that this release is vulnerable to the chunk > enconding problem? I have a Stronghold 3 release that WAS NO vulnerable. All Apache releases since Apache 1.2 are vulnerable to the chunked encoding issue, therefore so are all releases of Stronghold. We have been informed that the eEye tool was looking only at the returned server version to make its assesment of vulnerability, however that is not sufficient to find Stronghold (which changes the server version string), or servers that are not running Apache 1.3.26 but have been patched. [Although all releases of Stronghold are vulnerable the effects and exploitability vary from platform to platform. We suggest that all Stronghold users apply the patch or upgrade to the 3017 binaries] Cheers, Mark -- Mark J Cox / Red Hat / OpenSSL / Apache Software Foundation [email protected] // T: +44 798 061 3110 // F: +44 870 1319174