|
Family: Gentoo Local Security Checks --> Category: infos
[GLSA-200508-15] Apache 2.0: Denial of Service vulnerability Vulnerability Scan
Vulnerability Scan Summary Apache 2.0: Denial of Service vulnerability
Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200508-15
(Apache 2.0: Denial of Service vulnerability)
Filip Sneppe discovered that Apache improperly handles byterange
requests to CGI scripts.
Impact
A remote attacker may access vulnerable scripts in a malicious
way, exhausting all RAM and swap space on the server, resulting in a
Denial of Service of the Apache server.
Workaround
There is no known workaround at this time.
References:
http://issues.apache.org/bugzilla/show_bug.cgi?id=29962
Solution:
All apache users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-www/apache-2.0.54-r9"
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.
|