OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Wichert Akkerman (wichertwiggy.net)
Date: Wed Jun 19 2002 - 07:22:25 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    -----BEGIN PGP SIGNED MESSAGE-----

    - ------------------------------------------------------------------------
    Debian Security Advisory DSA-131-2 securitydebian.org
    http://www.debian.org/security/ Wichert Akkerman
    June 19, 2002
    - ------------------------------------------------------------------------

    Package : apache
    Problem type : remote DoS / exploit
    Debian-specific: no
    CVE name : CAN-2002-0392
    CERT advisory : VU#944335

    The DSA-131-1 advisory for the Apache chunk handling vulnerability
    contained an error and was missing some essential information:

    * The upstream fix was for the 1.3 series was made in version 1.3.26,
      not version 1.3.16 as the advisory incorrectly stated

    * The package upgrade does not restart the apache server automatically,
      this will have to be done manually. Please make sure your
      configuration is correct ("apachectl configtest" will verify that for
      you) and restart it using "/etc/init.d/apache restart"

    For details on the vulnerability and the updated packages please see
    the original advisory or visit the Debian security web-pages (available
    at http://www.debian.org/security/).

    - --
    - ----------------------------------------------------------------------------
    apt-get: deb http://security.debian.org/ stable/updates main
    dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
    Mailing list: debian-security-announcelists.debian.org

    -----BEGIN PGP SIGNATURE-----
    Version: 2.6.3ia
    Charset: noconv

    iQB1AwUBPRB3fajZR/ntlUftAQFOVwMAt2VnafXPwdKgXNfaAU/mHFa3jSOIMgZv
    08v2Ul4LP1eD5FvqGl3lqmxSc9bEOwrCbUG8LWO+Jbl/YNjSuBofi5DzLGhIlD/q
    UYVQn9Zvnr71d43qJ2Zwy9bltxl67Y8R
    =8J1R
    -----END PGP SIGNATURE-----

    -- 
    To UNSUBSCRIBE, email to debian-security-announce-requestlists.debian.org
    with a subject of "unsubscribe". Trouble? Contact listmasterlists.debian.org