GLSA: apache (200304-01)

From: Daniel Ahlberg (alizat_private)
Date: Wed Apr 09 2003 - 01:07:01 PDT

  • Next message: Conectiva Updates: "[CLA-2003:624] Conectiva Security Announcement - samba"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - - ---------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200304-01
    - - ---------------------------------------------------------------------
    
              PACKAGE : apache
              SUMMARY : Denial of service in Apache 2.x
                 DATE : 2003-04-09 08:06 UTC
              EXPLOIT : remote
    VERSIONS AFFECTED : 2.0.0-2.0.44
        FIXED VERSION : >=2.0.45
                  CVE : CAN-2003-0132
    
    - - ---------------------------------------------------------------------
    
    - From advisory:
    
    "Remote exploitation of a memory leak in the Apache HTTP Server causes the
    daemon to over utilize system resources on an affected system. The problem
    is HTTP Server's handling of large chunks of consecutive linefeed
    characters. The web server allocates an eighty-byte buffer for each
    linefeed character without specifying an upper limit for allocation.
    Consequently, an attacker can remotely exhaust system resources by
    generating many requests containing these characters."
    
    Read the full advisory at:
    http://www.idefense.com/advisory/04.08.03.txt
    
    SOLUTION
    
    It is recommended that all Gentoo Linux users who are running
    net-www/apache version 2  upgrade to apache-2.0.45 as follows:
    
    emerge sync
    emerge \=net-www/apache-2.0.45
    emerge clean
    
    - - ---------------------------------------------------------------------
    alizat_private - GnuPG key is available at http://cvs.gentoo.org/~aliz
    - - ---------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)
    
    iD8DBQE+k9ScfT7nyhUpoZMRAjRsAKCOSha1aZfqiR5D8HuCwBcpwXenLACfYDTD
    Nd0j+dcq/hf5VZ7FJ7H173Q=
    =8BkJ
    -----END PGP SIGNATURE-----
    



    This archive was generated by hypermail 2b30 : Wed Apr 09 2003 - 21:27:10 PDT