NASLDB: RHSA-2003-244: apache
General
ID: 12412
Name: RHSA-2003-244: apache
Summary: Check for the version of the apache packages
Credits: Tenable Network Security, Inc.
Classification
Risk: –
CVSS: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P
CVSS Base Vector: –
CVSS Temporal Vector: –
Port: 0
Family: Red Hat Local Security Checks
Type: Local
Description
Updated Apache and mod_ssl packages that fix several minor security issues
are now available for Red Hat Enterprise Linux.
The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.
Ben Laurie found a bug in the optional renegotiation code in mod_ssl
which can cause cipher suite restrictions to be ignored. This is triggered
if optional renegotiation is used (SSLOptions +OptRenegotiate) along with
verification of client certificates and a change to the cipher suite over
the renegotiation. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2003-0192 to this issue.
Apache does not filter terminal escape sequences from its error logs, which
could make it easier for attackers to insert those sequences into terminal
emulators containing vulnerabilities related to escape sequences. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CAN-2003-0020 to this issue.
It is possible to get Apache 1.3 to get into an infinite loop handling
internal redirects and nested subrequests. A patch for this issue adds a
new LimitInternalRecursion directive.
All users of the Apache HTTP Web Server are advised to upgrade to the
applicable errata packages, which contain back-ported fixes correcting
these issues.
After the errata packages are installed, restart the Web service by running
the following command:
/sbin/service httpd restart
Exploiting
Exploit Available: –
Exploitability Ease: –
Sources
CVE: CVE-2003-0020
OSVDB: –
Bugtraq: –
scipID: –
Timeline
Vulnerability Disclosure: –
Patch Release: –
Plugin Release: 2004/07/06
Plugin
Version: 1.12
Filename: redhat-RHSA-2003-244.nasl
Filesize: 3477 bytes
MD5 Hash: 3750aa3b6d210d1b87a45a19a48388c9
Identification: Host/RedHat/rpm-list
Require Keys: Host/RedHat/rpm-list
Dependencies: "ssh_get_info.nasl"
Copyright: This script is Copyright© 2004-2011 Tenable Network Security, Inc.
- Latest Plugins
- USN-1611-1 : thunderbird vulnerabilities
- USN-1610-1 : linux vulnerability
- USN-1609-1 : linux-ti-omap4 vulnerability
- SuSE 10 Security Update : PostgreSQL
- RHSA-2012-1364: bind97
- RHSA-2012-1363: bind
- RHSA-2012-1362: thunderbird
- RHSA-2012-1361: xulrunner
- Mandriva Linux Security Advisory : graphicsmagick
- FreeBSD : phpMyAdmin — Multiple XSS due to unescaped HTML output in Trigger, Procedure and Event pages and Fetching the version information from a non-SSL site is vulnerable to a MITM attack













