LWN.net Logo

Gentoo alert apache-20021015 (apache)

From:  Daniel Ahlberg <aliz@gentoo.org>
To:  bugtraq@securityfocus.com
Subject:  GLSA: apache
Date:  Tue, 15 Oct 2002 10:26:10 +0200

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200210-002 - - -------------------------------------------------------------------- PACKAGE : apache SUMMARY : shared memory scoreboard vulnerabilities EXPLOIT : local DATE : 2002-10-15 08:25 UTC - - -------------------------------------------------------------------- Apache HTTP Server contains a vulnerability in its shared memory scoreboard. Attackers who can execute commands under the Apache UID can either send a (SIGUSR1) signal to any process as root, in most cases killing the process, or launch a local denial of service (DoS) attack. Read the full advisory at http://www.idefense.com/advisory/10.03.02.txt SOLUTION It is recommended that all Gentoo Linux users who are running net-www/apache-1.3.26-r4 and earlier update their systems as follows: emerge rsync emerge apache emerge clean - - -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz - - -------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE9q9EifT7nyhUpoZMRAvMAAKC5uldCFmTfBWUELQUjdPUB63IX4ACeOIZi kXGG6Si1xe2JA+hdpT/TRSo= =Hawy -----END PGP SIGNATURE-----


(Log in to post comments)

Gentoo security update to apache

Posted Oct 16, 2002 22:39 UTC (Wed) by danielos (guest, #6053) [Link]

ok, it is good that the problem is fixed mainstream, but I suppose apache in
gentoo run as root by default, and not as nobody. I hope gentoo people fix
this problem too: there is no too much paranoic thing in securety.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds