|
Family: Debian Local Security Checks --> Category: infos
[DSA132] DSA-132-1 apache-ssl Vulnerability Scan
Vulnerability Scan Summary DSA-132-1 apache-ssl
Detailed Explanation for this Vulnerability Test
Mark Litchfield found a denial of service attack in the Apache
web-server. While investigating the problem the Apache Software
Foundation discovered that the code for handling invalid requests which
use chunked encoding also might allow arbitrary code execution on 64 bit
architectures.
This has been fixed in version 1.3.9.13-4.1 of the Debian apache-ssl
package and we recommend that you upgrade your apache-ssl package
immediately.
An update for the soon to be released Debian GNU/Linux 3.0/woody
distribution is not available at the moment.
More Information:
CVE-2002-0392,
VU#944335.
Solution : http://www.debian.org/security/2002/dsa-132
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|