LWN.net Logo

rPath alert rPSA-2006-0139-1 (httpd)

From:  "Justin M. Forbes" <jmforbes@rpath.com>
To:  security-announce@lists.rpath.com, update-announce@lists.rpath.com
Subject:  rPSA-2006-0139-1 httpd mod_ssl
Date:  Fri, 28 Jul 2006 15:16:19 -0400
Cc:  full-disclosure@lists.grok.org.uk, bugtraq@securityfocus.com, lwn@lwn.net

rPath Security Advisory: 2006-0139-1 Published: 2006-07-28 Products: rPath Linux 1 Rating: Major Exposure Level Classification: Remote System User Deterministic Unauthorized Access Updated Versions: httpd=/conary.rpath.com@rpl:devel//1/2.0.59-0.1-1 mod_ssl=/conary.rpath.com@rpl:devel//1/2.0.59-0.1-1 References: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200... https://issues.rpath.com/browse/RPL-538 Description: Previous versions of the httpd package contain a vulnerability in the mod_rewrite module. In some configurations, this vulnerability provides a remote attacker an opportunity to run arbitrary code as the httpd user. The default configuration of the httpd package is not not vulnerable to this attack because it does not provide any mod_rewrite rules that would enable the vulnerability.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds