| From: |
| Eren Turkay <eren@pardus.org.tr> |
| To: |
| pardus-security@pardus.org.tr |
| Subject: |
| [Pardus-security] [PLSA 2010-118] Apache: Denial of Service |
| Date: |
| Tue, 24 Aug 2010 12:01:35 +0300 (EEST) |
| Message-ID: |
| <20100824090135.1A7FDA7AB71@lider.pardus.org.tr> |
| Archive-link: |
| Article, Thread
|
------------------------------------------------------------------------
Pardus Linux Security Advisory 2010-118 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2010-08-24
Severity: 3
Type: Remote
------------------------------------------------------------------------
Summary
=======
A vulnerability has been fixed in Apache, which can be exploited by
malicious people to cause DoS.
Description
===========
CVE-2010-1452:
The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server
2.2.x before 2.2.16 allow remote attackers to cause a denial of service
(process crash) via a request that lacks a path.
Affected packages:
Pardus 2009:
apache, all before 2.2.16-37-12
Resolution
==========
There are update(s) for apache. You can update them via Package Manager
or with a single command from console:
pisi up apache
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=13945
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-...
------------------------------------------------------------------------
_______________________________________________
Pardus-security mailing list
Pardus-security@pardus.org.tr
http://liste.pardus.org.tr/mailman/listinfo/pardus-security
(
Log in to post comments)