Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 191603 - www-servers/apache: Security-relevant updates
Summary: www-servers/apache: Security-relevant updates
Status: RESOLVED DUPLICATE of bug 186219
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-09-07 14:34 UTC by Hanno Böck
Modified: 2011-10-30 22:38 UTC (History)
8 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hanno Böck gentoo-dev 2007-09-07 14:34:57 UTC
upstream released 2.0.61 and 2.2.6.

From release notes 2.2:
CVE-2007-3847: mod_proxy: Prevent reading past the end of a buffer when parsing date-related headers. PR 41144. 
CVE-2007-1863: mod_cache: Prevent a segmentation fault if attributes are listed in a Cache-Control header without any value. 
CVE-2007-3304: prefork, worker, event MPMs: Ensure that the parent process cannot be forced to kill processes outside its process group. 
CVE-2006-5752: mod_status: Fix a possible XSS attack against a site with a public server-status page and ExtendedStatus enabled, for browsers which perform charset "detection". Reported by Stefan Esser. 
CVE-2006-1862: mod_mem_cache: Copy headers into longer lived storage; header names and values could previously point to cleaned up storage. PR 41551.

release notes 2.0:
 
CVE-2007-3847: mod_proxy: Prevent reading past the end of a buffer when parsing date-related headers. PR 41144. 
CVE-2007-1863: mod_cache: Prevent segmentation fault if a Cache-Control header has no value. 
CVE-2006-5752: mod_status: Fix a possible XSS attack against a site with a public server-status page and ExtendedStatus enabled, for browsers which perform charset "detection". Reported by Stefan Esser. 
CVE-2007-3304: prefork, worker MPMs: Ensure that the parent process cannot be forced to kill processes outside its process group.
Comment 1 Benedikt Böhm (RETIRED) gentoo-dev 2007-09-07 21:48:19 UTC
2.0.61 and 2.2.6 now in cvs, fixes all security issues. see also #187258 and #186219
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-08 11:37:16 UTC

*** This bug has been marked as a duplicate of bug 186219 ***