Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 187258
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 186219
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Lars Hartmann <lars@chaotika.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 187258 depends on: Show dependency tree
Bug 187258 blocks: 187185

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-07-31 15:14 0000
Some vulnerabilities have been acknowledged in Apache, which can be exploited
by malicious, local users to cause a DoS (Denial of Service) and by malicious
people to conduct cross-site scripting attacks.

For more information:
SA25830

Solution:
Fixed in version 1.3.38-dev, 2.0.60-dev, and 2.2.5-dev.

Provided and/or discovered by:
Originally reported in a Red Hat advisory.

Original Advisory:
http://httpd.apache.org/security/vulnerabilities_13.html
http://httpd.apache.org/security/vulnerabilities_20.html
http://httpd.apache.org/security/vulnerabilities_22.html

Other References:
SA25830:
http://secunia.com/advisories/25830/

Reproducible: Always

------- Comment #1 From Benedikt Böhm 2007-07-31 22:31:19 0000 -------
backports for 2.2.4 are in svn and will be included in apache-2.2.4-r11 which
is scheduled for stabilization in roughly 2-3 weeks. no backports for 2.0.x

------- Comment #2 From Benedikt Böhm 2007-08-01 22:42:19 0000 -------
2.2.4-r11 is in cvs now

------- Comment #3 From Benedikt Böhm 2007-08-13 13:41:29 0000 -------
is security going to issue a GLSA or can we close this bug once apache-2.2 is
stable?

------- Comment #4 From Tobias Scherbaum 2007-08-13 15:10:16 0000 -------
(In reply to comment #1)
> no backports for 2.0.x
> 

What's the reason for not having a fixed 2.0.x ebuild? At least some
authentication modules changed from 2.0 to 2.2, so I'd prefer to not bite users
with this upgrade for security reasons.

------- Comment #5 From Sune Kloppenborg Jeppesen 2007-08-14 10:11:04 0000 -------
We're probably going to have a vote about GLSA release. Is 2.2.4-r11 ready for
stable marking?

------- Comment #6 From Tobias Scherbaum 2007-08-20 22:20:39 0000 -------
(In reply to comment #4)
> (In reply to comment #1)
> > no backports for 2.0.x
> > 
> 
> What's the reason for not having a fixed 2.0.x ebuild? At least some
> authentication modules changed from 2.0 to 2.2, so I'd prefer to not bite users
> with this upgrade for security reasons.
> 

*ping*

------- Comment #7 From Benedikt Böhm 2007-08-21 00:25:37 0000 -------
(In reply to comment #4)
> (In reply to comment #1)
> > no backports for 2.0.x
> > 
> 
> What's the reason for not having a fixed 2.0.x ebuild? At least some
> authentication modules changed from 2.0 to 2.2, so I'd prefer to not bite users
> with this upgrade for security reasons.
> 

after a lengthy svn search, i have added fixes for all CVEs for 2.0.59-r3
(there are four, one is not listed on the vuln page, but fixed in svn) ..
should be on the mirrors soon, and can be scheduled for stabilization, 2.2
stabilization will probably wait for 2.2.5, it will be released RSN and
contains all fixes ...

------- Comment #8 From Benedikt Böhm 2007-08-21 00:28:00 0000 -------
FYI, according to http://www.xatrix.org/cve.php?s=38514 the CVE for the fourth
issue seems unavailable currently...

------- Comment #9 From Benedikt Böhm 2007-08-26 10:37:56 0000 -------
unfortunately 2.0.59-r3 is completely broken since phreak backported config
changes, but not ebuild changes, causing quite a mess right now...

------- Comment #10 From Wolfram Schlich 2007-08-26 23:00:06 0000 -------
(In reply to comment #9)
> unfortunately 2.0.59-r3 is completely broken since phreak backported config
> changes, but not ebuild changes, causing quite a mess right now...
> 

what exactly does that mean?
what will happen when I upgrade from -r2 to -r3?

------- Comment #11 From Benedikt Böhm 2007-08-27 08:32:17 0000 -------
please use -r4, that has been fixed, and will go stable

------- Comment #12 From Benedikt Böhm 2007-09-07 21:48:25 0000 -------
2.0.61 and 2.2.6 in cvs now, fixes another security issue with 2.2.4-r12, see
#186219 and #191603

------- Comment #13 From Benedikt Böhm 2007-09-08 20:07:41 0000 -------
this is also handled by 186219

*** This bug has been marked as a duplicate of bug 186219 ***

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug