Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 187258 - www-servers/apache Denial of Service and Cross-Site Scripting
Summary: www-servers/apache Denial of Service and Cross-Site Scripting
Status: RESOLVED DUPLICATE of bug 186219
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/26273/
Whiteboard: B3 [stable]
Keywords: InVCS
Depends on:
Blocks: 187185
  Show dependency tree
 
Reported: 2007-07-31 15:14 UTC by Lars Hartmann
Modified: 2007-09-08 20:07 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lars Hartmann 2007-07-31 15:14:55 UTC
Some vulnerabilities have been acknowledged in Apache, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks.

For more information:
SA25830

Solution:
Fixed in version 1.3.38-dev, 2.0.60-dev, and 2.2.5-dev.

Provided and/or discovered by:
Originally reported in a Red Hat advisory.

Original Advisory:
http://httpd.apache.org/security/vulnerabilities_13.html
http://httpd.apache.org/security/vulnerabilities_20.html
http://httpd.apache.org/security/vulnerabilities_22.html

Other References:
SA25830:
http://secunia.com/advisories/25830/

Reproducible: Always
Comment 1 Benedikt Böhm (RETIRED) gentoo-dev 2007-07-31 22:31:19 UTC
backports for 2.2.4 are in svn and will be included in apache-2.2.4-r11 which is scheduled for stabilization in roughly 2-3 weeks. no backports for 2.0.x
Comment 2 Benedikt Böhm (RETIRED) gentoo-dev 2007-08-01 22:42:19 UTC
2.2.4-r11 is in cvs now
Comment 3 Benedikt Böhm (RETIRED) gentoo-dev 2007-08-13 13:41:29 UTC
is security going to issue a GLSA or can we close this bug once apache-2.2 is stable?
Comment 4 Tobias Scherbaum (RETIRED) gentoo-dev 2007-08-13 15:10:16 UTC
(In reply to comment #1)
> no backports for 2.0.x
> 

What's the reason for not having a fixed 2.0.x ebuild? At least some authentication modules changed from 2.0 to 2.2, so I'd prefer to not bite users with this upgrade for security reasons.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-08-14 10:11:04 UTC
We're probably going to have a vote about GLSA release. Is 2.2.4-r11 ready for stable marking?
Comment 6 Tobias Scherbaum (RETIRED) gentoo-dev 2007-08-20 22:20:39 UTC
(In reply to comment #4)
> (In reply to comment #1)
> > no backports for 2.0.x
> > 
> 
> What's the reason for not having a fixed 2.0.x ebuild? At least some
> authentication modules changed from 2.0 to 2.2, so I'd prefer to not bite users
> with this upgrade for security reasons.
> 

*ping*
Comment 7 Benedikt Böhm (RETIRED) gentoo-dev 2007-08-21 00:25:37 UTC
(In reply to comment #4)
> (In reply to comment #1)
> > no backports for 2.0.x
> > 
> 
> What's the reason for not having a fixed 2.0.x ebuild? At least some
> authentication modules changed from 2.0 to 2.2, so I'd prefer to not bite users
> with this upgrade for security reasons.
> 

after a lengthy svn search, i have added fixes for all CVEs for 2.0.59-r3 (there are four, one is not listed on the vuln page, but fixed in svn) .. should be on the mirrors soon, and can be scheduled for stabilization, 2.2 stabilization will probably wait for 2.2.5, it will be released RSN and contains all fixes ...
Comment 8 Benedikt Böhm (RETIRED) gentoo-dev 2007-08-21 00:28:00 UTC
FYI, according to http://www.xatrix.org/cve.php?s=38514 the CVE for the fourth issue seems unavailable currently...
Comment 9 Benedikt Böhm (RETIRED) gentoo-dev 2007-08-26 10:37:56 UTC
unfortunately 2.0.59-r3 is completely broken since phreak backported config changes, but not ebuild changes, causing quite a mess right now...
Comment 10 Wolfram Schlich (RETIRED) gentoo-dev 2007-08-26 23:00:06 UTC
(In reply to comment #9)
> unfortunately 2.0.59-r3 is completely broken since phreak backported config
> changes, but not ebuild changes, causing quite a mess right now...
> 

what exactly does that mean?
what will happen when I upgrade from -r2 to -r3?
Comment 11 Benedikt Böhm (RETIRED) gentoo-dev 2007-08-27 08:32:17 UTC
please use -r4, that has been fixed, and will go stable
Comment 12 Benedikt Böhm (RETIRED) gentoo-dev 2007-09-07 21:48:25 UTC
2.0.61 and 2.2.6 in cvs now, fixes another security issue with 2.2.4-r12, see #186219 and #191603
Comment 13 Benedikt Böhm (RETIRED) gentoo-dev 2007-09-08 20:07:41 UTC
this is also handled by 186219

*** This bug has been marked as a duplicate of bug 186219 ***