http://www.mandriva.com/en/
______________________________
Package : apache
Date : July 30, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
Updated apache package fixes security vulnerabilities:
A race condition flaw, leading to heap-based buffer overflows,
was found in the mod_status httpd module. A remote attacker able to
access a status page served by mod_status on a server using a threaded
Multi-Processing Module (MPM) could send a specially crafted request
that would cause the httpd child process to crash or, possibly,
allow the attacker to execute arbitrary code with the privileges of
the apache user (CVE-2014-0226).
A denial of service flaw was found in the way httpd's mod_deflate
module handled request body decompression (configured via the DEFLATE
input filter). A remote attacker able to send a request whose body
would be decompressed could use this flaw to consume an excessive
amount of system memory and CPU on the target system (CVE-2014-0118).
A denial of service flaw was found in the way httpd's mod_cgid module
executed CGI scripts that did not read data from the standard input. A
remote attacker could submit a specially crafted request that would
cause the httpd child process to hang indefinitely (CVE-2014-0231).
______________________________
References:
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://cve.mitre.org/cgi-bin/
http://advisories.mageia.org/
______________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
e7ed0d96bdef964dcb281969c84ee2
630779667690cc0344dc3a130922ef
02f62e776b47bc71917bacc5301166
5ac808d10784e0a0fed1b1238e965d
12d7209a6ac1af471fef5754d1efe9
08e3be5cd2f1b233ead6ba70ee9a7e
9ca153c3ee32b84a5d6e694426d93b
a7df22dbf57ad3f926300dd250a8a3
93fd5123adf783e19a7e77c49bb2ba
e967eab04bbfefc1c038460652834e
44c6603d4f40f820b702d107e36783
e257e68818d03a7e05f99f872aadb7
7636b2db4a8461242f3eaa58ca6c58
795f09dd6508ce6f84683c0a4e0f50
31549291edb6d91b20dda3bbf4376f
231002ea53e9c7b1fdf78d2b415e7e
c5ec340109b8eb0aa36113ea2b9dff
7b20b71e0c7e424212d2b941cc8e70
fb27d8413c6f22b94af69e23084e61
3965833259f643f0a7141451e442c7
2b7434565978780882e69bbaa91029
7c350be0d459259ce9c49c1cf51564
ef3a271c37fde6b19ab6adaacd3fd0
cd7752c067797c22144f5299fe782d
7d8576115cb675340084b8fbf884fb
8fd89d82d258f6cdfab8bc8bfa5818
5dd921dbff39365fa187e6a24975e5
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą