Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 64145
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 64145 depends on: 62626 Show dependency tree
Bug 64145 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-09-15 09:19 0000
IPv6 URI parsing can cause crash CAN-2004-0786 

Testing using the Codenomicon HTTP Test Tool performed by the Apache Software Foundation security group and Red Hat uncovered an input validation issue in the IPv6 URI parsing routines in the apr-util library. If a remote attacker sent a request including a carefully crafted URI, an httpd child process could be made to crash. One some BSD systems it is believed this flaw may be able to lead to remote code execution. 

Affects: 2.0.50, 2.0.49, 2.0.48, 2.0.47, 2.0.46, 2.0.45, 2.0.44, 2.0.43, 2.0.42, 2.0.40, 2.0.39, 2.0.37, 2.0.36, 2.0.35

 

Environment variable expansion flaw CAN-2004-0747 

The Swedish IT Incident Centre (SITIC) reported a buffer overflow in the expansion of environment variables during configuration file parsing. This issue could allow a local user to gain the privileges of a httpd child if a server can be forced to parse a carefully crafted .htaccess file written by a local user. 

Affects: 2.0.50, 2.0.49, 2.0.48, 2.0.47, 2.0.46, 2.0.45, 2.0.44, 2.0.43, 2.0.42, 2.0.40, 2.0.39, 2.0.37, 2.0.36, 2.0.35

---

Patches are here:

http://www.apache.org/dist/httpd/patches/apply_to_2.0.50/

------- Comment #1 From Thierry Carrez (RETIRED) 2004-09-15 09:25:27 0000 -------
No, not again...
Stuart : a 2.0.51 ebuild would be nice :)

------- Comment #2 From Stuart Herbert (RETIRED) 2004-09-15 15:42:39 0000 -------
Done.  Might as well combine this w/ 62626 tbh now.

Best regards,
Stu

------- Comment #3 From Matthias Geerdsen 2004-09-16 00:49:48 0000 -------
stable marking being handled in bug #62626

------- Comment #4 From Thierry Carrez (RETIRED) 2004-09-16 13:59:11 0000 -------
GLSA 200409-21

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug