Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 53544 - net-www/apache-1.3: Buffer overflow in apache mod_proxy
Summary: net-www/apache-1.3: Buffer overflow in apache mod_proxy
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: Highest major (vote)
Assignee: Gentoo Security
URL: http://www.guninski.com/modproxy1.html
Whiteboard: B1 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2004-06-10 10:22 UTC by Sune Kloppenborg Jeppesen
Modified: 2011-10-30 22:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---
jaervosz: Assigned_To? (jaervosz)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen gentoo-dev 2004-06-10 10:22:33 UTC
This could cause a Denial of Service and under certain circumstances cause arbitrary code execution.

A fix is available here:

http://marc.theaimsgroup.com/?l=apache-httpd-dev&m=108687304202140
Comment 1 Chuck Short (RETIRED) gentoo-dev 2004-06-10 15:39:47 UTC
The patch hasnt made it into upstream yet...still waiting.

chuck
Comment 2 Chuck Short (RETIRED) gentoo-dev 2004-06-11 11:52:05 UTC
Patch has been added and version bumped. Please have other arches test. web-apps herd should have to be notified about apache bugs.

Thanks
chuck
Comment 3 Sune Kloppenborg Jeppesen gentoo-dev 2004-06-11 12:57:52 UTC
x86 ppc sparc mips alpha hppa amd64 ia64: please mark stable
Comment 4 Bryan Østergaard (RETIRED) gentoo-dev 2004-06-11 21:17:12 UTC
Stable on alpha.
Comment 5 Jason Wever (RETIRED) gentoo-dev 2004-06-12 16:39:17 UTC
Stable on sparc
Comment 6 Joshua Kinard gentoo-dev 2004-06-12 18:42:37 UTC
Stable on mips
Comment 7 Brandon Hale (RETIRED) gentoo-dev 2004-06-15 19:18:33 UTC
Stable on x86.
Comment 8 Guy Martin (RETIRED) gentoo-dev 2004-06-16 02:39:34 UTC
Stable on hppa.
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2004-06-16 08:58:14 UTC
GLSA is ready.
ppc, amd64: please mark stable so it can go out :)
Comment 10 Luca Barbato gentoo-dev 2004-06-21 06:34:35 UTC
Stable on ppc too
Comment 11 Danny van Dyk (RETIRED) gentoo-dev 2004-06-21 12:45:13 UTC
Stable on amd64. Sorry for the delay.
Comment 12 Thierry Carrez (RETIRED) gentoo-dev 2004-06-21 14:09:27 UTC
GLSA 200406-16