Family: Debian Local Security Checks --> Category: infos
[DSA132] DSA-132-1 apache-ssl Vulnerability Scan
Vulnerability Scan Summary
Detailed Explanation for this Vulnerability Test
Mark Litchfield found a denial of service attack in the Apache
web-server. While investigating the problem the Apache Software
Foundation discovered that the code for handling invalid requests which
use chunked encoding also might allow arbitrary code execution on 64 bit
This has been fixed in version 126.96.36.199-4.1 of the Debian apache-ssl
package and we recommend that you upgrade your apache-ssl package
An update for the soon to be released Debian GNU/Linux 3.0/woody
distribution is not available at the moment.
Solution : http://www.debian.org/security/2002/dsa-132
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.