Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 66807
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Stuart Herbert (RETIRED) <stuart@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 66807 depends on: Show dependency tree
Bug 66807 blocks:
Votes: 0    Show votes for this bug    Vote for this bug

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-10-08 13:55 0000
I've added net-www/apache-2.0.52 to the Portage tree.  This package includes an
additional patch to address security issue CAN-2004-0885.

It's ready for testing and marking stable on all arches.

My thanks to Paul Querna <pquerna@apache.org> for letting us know about this.

Best regards,
Stu

------- Comment #1 From Thierry Carrez (RETIRED) 2004-10-08 14:06:30 0000 -------
Arches: please mark net-www/apache-2.0.52 stable :)

------- Comment #2 From Jason Wever (RETIRED) 2004-10-08 19:40:48 0000 -------
Stable on sparc.

------- Comment #3 From Bryan Østergaard (RETIRED) 2004-10-09 05:14:53 0000 -------
Stable on alpha.

------- Comment #4 From Jochen Maes (RETIRED) 2004-10-09 05:19:32 0000 -------
stable on ppc

------- Comment #5 From Tom Gall 2004-10-09 11:32:08 0000 -------
stable on ppc64, thanks!

------- Comment #6 From SpanKY 2004-10-11 18:54:25 0000 -------
arm/hppa/ia64/s390 stable

------- Comment #7 From Thierry Carrez (RETIRED) 2004-10-13 02:42:41 0000 -------
x86, amd64: please mark stable so that the GLSA can go out.

------- Comment #8 From Olivier Crete 2004-10-13 09:53:39 0000 -------
x86 stable.. 

------- Comment #9 From Hardave Riar (RETIRED) 2004-10-14 03:15:54 0000 -------
Stable on mips.

------- Comment #10 From Matthias Geerdsen 2004-10-15 12:24:07 0000 -------
apache herd, mod_ssl seems vulnerable to this too and version 2.8.20 is out to
fix this

CHANGES entry for this version:

Changes with mod_ssl 2.8.20 (16-Jul-2004 to 15-Oct-2004)

   *) With OpenSSL 0.9.7, prevent session resumption during a
      renegotiation to force the client to negotiate a new (and
      acceptable to mod_ssl) cipher suite. Additionally, ensure
      that a correct cipher suite has been negotiated afterwards
      (CAN-2004-0885).

   *) Fixed more printf(3) style format string bugs (not security
      related) which could crash the server if mod_ssl's trace
      or debug log level is enabled

___
http://secunia.com/advisories/12847/
VE reference:   CAN-2004-0885

Description:
Hartmut Keil has reported a security issue in mod_ssl, which can be exploited
by malicious people to bypass certain security restrictions.

For more information:
SA12787

Solution:
Update to version 2.8.20-1.3.31.
http://www.modssl.org/

Provided and/or discovered by:
Hartmut Keil

------- Comment #11 From Thierry Carrez (RETIRED) 2004-10-15 13:43:44 0000 -------
*** Bug 67711 has been marked as a duplicate of this bug. ***

------- Comment #12 From Matthias Geerdsen 2004-10-18 00:37:05 0000 -------
removing amd64 since apache is all done already, thanks Kugelfang :-)

any progress on an updated mod_ssl ebuild?

------- Comment #13 From Thierry Carrez (RETIRED) 2004-10-19 00:49:48 0000 -------
Apache team, please bump mod_ssl to 2.8.20...

------- Comment #14 From Bryan Østergaard (RETIRED) 2004-10-20 18:51:10 0000 -------
mod_ssl-2.8.20 is now in cvs.

------- Comment #15 From Luke Macken (RETIRED) 2004-10-20 21:34:38 0000 -------
mod_ssl-2.8.20 marked stable by maintainer.

marking glsa bug-ready.

------- Comment #16 From Thierry Carrez (RETIRED) 2004-10-22 01:21:32 0000 -------
GLSA 200410-21

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug