drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Pufferüberlauf in apache
Name: |
Pufferüberlauf in apache
|
|
ID: |
SSA:2004-305-01 |
|
Distribution: |
Slackware |
|
Plattformen: |
Slackware -current, Slackware 8.1, Slackware 9.0, Slackware 9.1, Slackware 10.0 |
|
Datum: |
Mo, 1. November 2004, 12:00 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0492
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0940 |
|
Applikationen: |
mod_ssl |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
[slackware-security] apache+mod_ssl (SSA:2004-305-01)
New apache packages are available for Slackware 8.1, 9.0, 9.1, 10.0, and -current to fix a security issue. Apache has been upgraded to version 1.3.33 which fixes a buffer overflow which may allow local users to execute arbitrary code as the apache user.
The mod_ssl package has also been upgraded to version 2.8.22_1.3.33.
More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0940
Here are the details from the Slackware 10.0 ChangeLog: +--------------------------+ patches/packages/apache-1.3.33-i486-1.tgz: Upgraded to apache-1.3.33. This fixes one new security issue (the first issue, CAN-2004-0492, was fixed in apache-1.3.33). The second bug fixed in 1.3.3 (CAN-2004-0940) allows a local user who can create SSI documents to become "nobody". The amount of mischief they could cause as nobody seems low at first glance, but it might allow them to use kill or killall as nobody to try to create a DoS. Mention PHP's mhash dependency in httpd.conf (thanks to Jakub Jankowski). (* Security fix *) patches/packages/mod_ssl-2.8.22_1.3.33-i486-1.tgz: Upgraded to mod_ssl-2.8.22_1.3.33. +--------------------------+
Where to find the new packages: +-----------------------------+
Updated packages for Slackware 8.1: apache-1.3.33-i386-1.tgz mod_ssl-2.8.22_1.3.33-i386-1.tgz
Updated packages for Slackware 9.0: apache-1.3.33-i386-1.tgz mod_ssl-2.8.22_1.3.33-i386-1.tgz
Updated packages for Slackware 9.1: apache-1.3.33-i486-1.tgz mod_ssl-2.8.22_1.3.33-i486-1.tgz
Updated packages for Slackware 10.0: apache-1.3.33-i486-1.tgz mod_ssl-2.8.22_1.3.33-i486-1.tgz
Updated packages for Slackware -current: apache-1.3.33-i486-1.tgz mod_ssl-2.8.22_1.3.33-i486-1.tgz
MD5 signatures: +-------------+
Slackware 8.1 packages: 53a9c132945eb4335aacfcb21d5996e0 apache-1.3.33-i386-1.tgz b0a95e205d3e88597aa9f1241ca7354f mod_ssl-2.8.22_1.3.33-i386-1.tgz
Slackware 9.0 packages: 429df7fa01205e5c12d3728f4987609f apache-1.3.33-i386-1.tgz af8345a9edf17dbd4e141b46d908990a mod_ssl-2.8.22_1.3.33-i386-1.tgz
Slackware 9.1 packages: adb43447a8abcb7a6100343585d762db apache-1.3.33-i486-1.tgz 00c1338c5c6db89960eb53ac4495ba41 mod_ssl-2.8.22_1.3.33-i486-1.tgz
Slackware 10.0 packages: 22db37b8d3e7a32b75a274520e11e272 apache-1.3.33-i486-1.tgz 1968e2361039e07f69658665dafcf56a mod_ssl-2.8.22_1.3.33-i486-1.tgz
Slackware -current packages: c450863cad0ed3771fea628d506b8caf apache-1.3.33-i486-1.tgz 44fdebabf6130cd2fc4e048f5d619683 mod_ssl-2.8.22_1.3.33-i486-1.tgz
Installation instructions: +------------------------+
First, stop apache:
# apachectl stop
Next, upgrade the Apache package as root:
# upgradepkg apache-1.3.33-i486-1.tgz
For mod_ssl users, IMPORTANT: Backup any keys/certificates you wish to save for mod_ssl (in /etc/apache/ssl.*), then upgrade mod_ssl:
# upgradepkg mod_ssl-2.8.22_1.3.33-i486-1.tgz
If necessary, restore any mod_ssl config files.
Finally, restart apache:
# apachectl start
Or, if you're running a secure server with mod_ssl:
# apachectl startssl
+-----+
Slackware Linux Security Team security@slackware.com Slackware Packages and Security Alerts are always signed with this GPG key: http://slackware.com/gpg-key
+------------------------------------------------------------------------+ | To leave the slackware-security mailing list: | +------------------------------------------------------------------------+ | Send an email to majordomo@slackware.com with this text in the body of | | the email message: | | | | unsubscribe slackware-security | | | | You will get a confirmation message back containing instructions to | | complete the process. Please do not reply to this email address. | +------------------------------------------------------------------------+
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux)
iD8DBQFBhcMDakRjwEAQIjMRAlCIAJ9UqTZdS93OGpVt5QYZcBqpyeyjPACdHh/l 7+CvVcdpzpCUCCSy6Gv1n2s= =xezg -----END PGP SIGNATURE-----
|
|
|
|