http://www.mandriva.com/en/
______________________________
Package : apache
Date : September 4, 2014
Affected: Business Server 1.0
______________________________
Problem Description:
A vulnerability has been found and corrected in apache (ASF HTTPD):
The mod_headers module in the Apache HTTP Server 2.2.22 allows
remote attackers to bypass RequestHeader unset directives by placing
a header in the trailer portion of data sent with chunked transfer
coding. NOTE: the vendor states this is not a security issue in httpd
as such. (CVE-2013-5704).
The updated packages have been upgraded to the latest 2.2.29 version
which is not vulnerable to this issue.
______________________________
References:
http://cve.mitre.org/cgi-bin/
https://httpd.apache.org/
http://svn.apache.org/repos/
______________________________
Updated Packages:
Mandriva Business Server 1/X86_64:
29750abc525fa1f663282d28915272
721035ffb6d7d21074f35717e3f44a
26297afb85c6296c32e00126ac40ea
e53712739979bb6a1cd6c85165b124
7fe720b46b6ebad13e251a9f36bbb2
9f09d825cfd11dc8f8027ac3bd1c26
7d1ffd5f5df3200633bbb199b7c152
47ac5b86d4abcf7da0bfbbe9746738
30d1f26436b3db46048646ef958efd
ba2f01b8e532bb6d799a4001625051
fe40c02ee1cbdd83112356de42a2a6
496a38cfceda7248fd711545dae768
7628aa8f44becd4df7e0b3b6479709
9e04002218f22396cdfd2cb889da3e
db545b5ea18345ddf4e4e16b4f0fac
95d3fa71a040403e77c943d6923a90
388a8240499cec37971a6ce592da41
d5e371ec472c6a05be68f872250274
d20e4fd4af86f72b2c73f046d5ae53
f045696188805a71bddedbf4fbfc09
2d3e37248a242d1106ede4d5ab1233
4bed9538651df001dc99eceec5022f
2502b612c9679119ea0c106db3c8b3
a9611bd147a083dbd69bccc2c3dfc2
a9a25d4cca89ac9941324f5adef736
1ed209164c99e8430f4265d0c85007
3e21e977464838c686fc1e07b9a9e6
______________________________
To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.
All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:
gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
You can view other update advisories for Mandriva Linux at:
http://www.mandriva.com/en/
If you want to report vulnerabilities, please contact
security_(at)_mandriva.com
Komentarų nėra:
Rašyti komentarą