Wollt's nur mal angemerkt haben, für den fall dass hier ein Nutzer mit Apache2 sich aus irgend einem Grund nicht in die Apache-Mailinglists eingetragen hat:
Apache 2.0.46 wurde released, darin wurden 2 Sicherheitslöcher gefixt. Ein Update wird dringend empfohlen. Genaueres über die Sicherheitslöcher gibts am Freitag, bis dahin sollte man das Update gemacht haben ;)
Security Update für Apache 2
-
- Posts: 2138
- Joined: 2002-12-15 00:10
- Location: Bergheim
Re: Security Update für Apache 2
Warum erst Freitag?
Apache 2.0.46 Major changes
Security vulnerabilities closed since Apache 2.0.45
*) SECURITY [CAN-2003-0245]: Fixed a bug that could be triggered
remotely through mod_dav and possibly other mechanisms, causing
an Apache child process to crash. The crash was first reported
by David Endler <DEndler@iDefense.com> and was researched and
fixed by Joe Orton <jorton@redhat.com>. Details will be released
on 30 May 2003.
*) SECURITY [CAN-2003-0189]: Fixed a denial-of-service vulnerability
affecting basic authentication on Unix platforms related to
thread-safety in apr_password_validate(). The problem was reported
by John Hughes <john.hughes@entegrity.com>
Apache 2.0.46 Major changes
Security vulnerabilities closed since Apache 2.0.45
*) SECURITY [CAN-2003-0245]: Fixed a bug that could be triggered
remotely through mod_dav and possibly other mechanisms, causing
an Apache child process to crash. The crash was first reported
by David Endler <DEndler@iDefense.com> and was researched and
fixed by Joe Orton <jorton@redhat.com>. Details will be released
on 30 May 2003.
*) SECURITY [CAN-2003-0189]: Fixed a denial-of-service vulnerability
affecting basic authentication on Unix platforms related to
thread-safety in apr_password_validate(). The problem was reported
by John Hughes <john.hughes@entegrity.com>
-
- Posts: 339
- Joined: 2002-05-27 10:52
Re: Security Update für Apache 2
Weil, sobald die Details rausbringen, die kiddies anfangen Exploits zu schreiben...
-
- Userprojekt
- Posts: 3247
- Joined: 2002-07-18 08:13
- Location: München
Re: Security Update für Apache 2
Naja, CERT haben die doch wohl auch abonniert... :P
Meine Exploits liegen schon auf der Platte... *g*
Meine Exploits liegen schon auf der Platte... *g*