Re: latest security hole

Andreas Deller <[email protected]> Tue, 9 Jul 2002 08:17:49 +0200 (MEST)
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
Yes, it applies to it.

http://www.cert.org/advisories/CA-2002-17.html lists all affected systems,
among others 
'Web servers based on Apache code versions 1.3 through 1.3.24'.
Since build 3014 is based on 1.3.19 (see also RELEASE_NOTES),
you need to apply the patch to this build.

Earlier posts in this mailing list show a diff between the
patched and the unpatched version for http_protocol.c which
you can apply and the recompile Stronghold.

Regards
	Andy


> From [email protected]  Mon Jul  8 17:21:34 2002
> Delivered-To: [email protected]
> Delivered-To: [email protected]
> From: lz <[email protected]>
> To: [email protected]
> MIME-Version: 1.0
> X-Loop: [email protected]
> Subject: [Stronghold-users] latest security hole
> X-BeenThere: [email protected]
> X-Mailman-Version: 2.0.1
> List-Help: <mailto:[email protected]?subject=help>
> List-Post: <mailto:[email protected]>
> List-Subscribe: <https://listman.redhat.com/mailman/listinfo/stronghold-users>,
> 	<mailto:[email protected]?subject=subscribe>
> List-Id: Red Hat Stronghold Users List <stronghold-users.redhat.com>
> List-Unsubscribe: <https://listman.redhat.com/mailman/listinfo/stronghold-users>,
> 	<mailto:[email protected]?subject=unsubscribe>
> List-Archive: <https://listman.redhat.com/pipermail/stronghold-users/>
> Date: Mon, 8 Jul 2002 08:20:58 -0700 (PDT)
> 
> Hi guys,
> 
> I am using StrongHold 3.0/Apache 1.3.19, Build 3014.
> 
> For some reason patch to fix chunk size vulnerability
> is available for only Builds 3016 and up. Do you think
> the security hole applies to my case?
> 
> Thank you!