|
Family: Slackware Local Security Checks --> Category: infos
SSA-2005-310-04 apache Vulnerability Scan
Vulnerability Scan Summary SSA-2005-310-04 apache
Detailed Explanation for this Vulnerability Test
New apache packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1,
10.2, and -current to fix potential security issues:
* If a request contains both Transfer-Encoding and Content-Length
headers, remove the Content-Length, mitigating some HTTP Request
Splitting/Spoofing attacks.
* Added TraceEnable [on|off|extended] per-server directive to alter
the behavior of the TRACE method.
It's hard to say how much real-world impact these have, as there's no more
information about that in the announcement. The original Apache announement
can be read here:
http://www.apache.org/dist/httpd/Announcement1.3.html
Note that if you use mod_ssl, you will also need a new mod_ssl package. These
have been provided for the same releases of Slackware.
Click HERE for more information and discussions on this network vulnerability scan.
|