98295 2003-04-10  06:27  /50 rader/ Daniel Ahlberg <aliz@gentoo.org>
Importerad: 2003-04-10  06:27  av Brevbäraren
Extern mottagare: bugtraq@securityfocus.com
Mottagare: Bugtraq (import) <4434>
Ärende: GLSA:  apache (200304-01)
------------------------------------------------------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200304-01
- - ---------------------------------------------------------------------

          PACKAGE : apache
          SUMMARY : Denial of service in Apache 2.x
             DATE : 2003-04-09 08:06 UTC
          EXPLOIT : remote
VERSIONS AFFECTED : 2.0.0-2.0.44
    FIXED VERSION : >=2.0.45
              CVE : CAN-2003-0132

- - ---------------------------------------------------------------------

- From advisory:

"Remote exploitation of a memory leak in the Apache HTTP Server
causes the daemon to over utilize system resources on an affected
system. The problem is HTTP Server's handling of large chunks of
consecutive linefeed characters. The web server allocates an
eighty-byte buffer for each linefeed character without specifying an
upper limit for allocation.  Consequently, an attacker can remotely
exhaust system resources by generating many requests containing these
characters."

Read the full advisory at:
http://www.idefense.com/advisory/04.08.03.txt

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-www/apache version 2  upgrade to apache-2.0.45 as follows:

emerge sync
emerge \=net-www/apache-2.0.45
emerge clean

- - ---------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz
- - ---------------------------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+k9ScfT7nyhUpoZMRAjRsAKCOSha1aZfqiR5D8HuCwBcpwXenLACfYDTD
Nd0j+dcq/hf5VZ7FJ7H173Q=
=8BkJ
-----END PGP SIGNATURE-----
(98295) /Daniel Ahlberg <aliz@gentoo.org>/(Ombruten)