Re: help in patching

peredina <[email protected]> Wed, 26 Jun 2002 07:34:00 -0400
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
I dont work for eEye, but from my tests, I can say that is NOT true.

I have tested the tool with patched, and unpatched versions of 1.3.20 
(setting both generic banners and default banners), and it does not 
appear to be looking at the banners.

In all my tests, the vulnerability scan picked up the correct 
information regarding the fix.

Im not telling anyone they shouldnt upgrade, Im just letting you know 
what I've found out about the eEye tool personally....I've already 
upgraded what I've had to.

Thanks,

Curt

Mark J Cox wrote:
>>Did you actually verify that this release is vulnerable to the chunk 
>>enconding problem? I have a Stronghold 3 release that WAS NO vulnerable.
> 
> 
> All Apache releases since Apache 1.2 are vulnerable to the chunked
> encoding issue, therefore so are all releases of Stronghold.  We have been
> informed that the eEye tool was looking only at the returned server
> version to make its assesment of vulnerability, however that is not
> sufficient to find Stronghold (which changes the server version string),
> or servers that are not running Apache 1.3.26 but have been patched.
> 
> [Although all releases of Stronghold are vulnerable the effects and
> exploitability vary from platform to platform.  We suggest that all
> Stronghold users apply the patch or upgrade to the 3017 binaries]
> 
> Cheers, Mark
> --
> Mark J Cox / Red Hat / OpenSSL / Apache Software Foundation
> [email protected] // T: +44 798 061 3110 // F: +44 870 1319174
> 
> 
> 
> 
> _______________________________________________
> Stronghold-users mailing list
> [email protected]
> https://listman.redhat.com/mailman/listinfo/stronghold-users