Re: latest security hole
Andreas Deller <[email protected]> Tue, 9 Jul 2002 08:17:49 +0200 (MEST)
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <[email protected]> |
Yes, it applies to it. http://www.cert.org/advisories/CA-2002-17.html lists all affected systems, among others 'Web servers based on Apache code versions 1.3 through 1.3.24'. Since build 3014 is based on 1.3.19 (see also RELEASE_NOTES), you need to apply the patch to this build. Earlier posts in this mailing list show a diff between the patched and the unpatched version for http_protocol.c which you can apply and the recompile Stronghold. Regards Andy > From [email protected] Mon Jul 8 17:21:34 2002 > Delivered-To: [email protected] > Delivered-To: [email protected] > From: lz <[email protected]> > To: [email protected] > MIME-Version: 1.0 > X-Loop: [email protected] > Subject: [Stronghold-users] latest security hole > X-BeenThere: [email protected] > X-Mailman-Version: 2.0.1 > List-Help: <mailto:[email protected]?subject=help> > List-Post: <mailto:[email protected]> > List-Subscribe: <https://listman.redhat.com/mailman/listinfo/stronghold-users>, > <mailto:[email protected]?subject=subscribe> > List-Id: Red Hat Stronghold Users List <stronghold-users.redhat.com> > List-Unsubscribe: <https://listman.redhat.com/mailman/listinfo/stronghold-users>, > <mailto:[email protected]?subject=unsubscribe> > List-Archive: <https://listman.redhat.com/pipermail/stronghold-users/> > Date: Mon, 8 Jul 2002 08:20:58 -0700 (PDT) > > Hi guys, > > I am using StrongHold 3.0/Apache 1.3.19, Build 3014. > > For some reason patch to fix chunk size vulnerability > is available for only Builds 3016 and up. Do you think > the security hole applies to my case? > > Thank you!