First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 128610
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Jasper Bryant-Greene <jasper@album.co.nz>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 128610 depends on: Show dependency tree
Bug 128610 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-04-03 01:05 0000
- --------------------------------------------------------------------------
Debian Security Advisory DSA 1000-2                    security@debian.org
http://www.debian.org/security/                             Martin Schulze
April 3rd, 2006                         http://www.debian.org/security/faq
- --------------------------------------------------------------------------

Package        : libapreq2-perl
Vulnerability  : design error
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2006-0042
BugTraq ID     : 16710
Debian Bug     : 354060 358689

Gunnar Wolf noticed that the correction for the following problem was
not complete and requires an update.  For completeness we're
providing the original problem description:

   An algorithm weakness has been discovered in Apache2::Request, the
   generic request library for Apache2 which can be exploited remotely
   and cause a denial of service via CPU consumption.

The old stable distribution (woody) does not contain this package.

For the stable distribution (sarge) this problem has been fixed in
version 2.04-dev-1sarge2.

For the unstable distribution (sid) this problem has been fixed in
version 2.07-1.

We recommend that you upgrade your libapreq2, libapache2-mod-apreq2
and libapache2-request-perl packages.

------- Comment #1 From Stefan Cornelius (RETIRED) 2006-04-03 01:22:22 0000 -------
pcc and x86 please mark stable, thank you.

------- Comment #2 From Tobias Scherbaum 2006-04-03 10:25:47 0000 -------
ppc stable

------- Comment #3 From Bryan Østergaard (RETIRED) 2006-04-08 15:44:36 0000 -------
Stable on x86.

------- Comment #4 From Raphael Marichez 2006-04-08 15:48:55 0000 -------
nice :)

CPU consumption : not sure a GLSA is needed. Really not.

------- Comment #5 From Thierry Carrez (RETIRED) 2006-04-09 03:51:15 0000 -------
I tend to vote yes. DoS on apache (even by CPU consumption) is nasty.

------- Comment #6 From Stefan Cornelius (RETIRED) 2006-04-09 09:59:07 0000 -------
i vote yes here - as Koon said, DoSing apache is evil.

------- Comment #7 From Sune Kloppenborg Jeppesen 2006-04-09 12:33:50 0000 -------
I tend to vote YES too, so let's have a GLSA.

------- Comment #8 From Thierry Carrez (RETIRED) 2006-04-17 10:39:46 0000 -------
GLSA 200604-08, thx everyone

First Last Prev Next    No search results available      Search page      Enter new bug