LWN.net Logo

RHEL apache builds not affected

RHEL apache builds not affected

Posted Jul 29, 2006 17:20 UTC (Sat) by dowdle (subscriber, #659)
Parent article: Apache update for a remote vulnerability

Recently added to Red Hat's Knowledgebase:

Is Red Hat Enterprise Linux vulnerable to the Apache mod_rewrite off-by-one vulnerability (CVE-2006-3747)?

Resolution:
This issue does not affect the version of Apache httpd as supplied with Red Hat Enterprise Linux 2.1 as it does not contain the vulnerable code.

The ability to exploit this issue is dependent on the stack layout for a particular compiled version of mod_rewrite. If the compiler has added padding to the stack immediately after the buffer being overwritten, this issue can not be exploited, and Apache httpd will continue operating normally.

The Red Hat Security Response Team analyzed Red Hat Enterprise Linux 3 and Red Hat Enterprise Linux 4 binaries for all architectures as packaged by Red Hat and determined that these versions cannot be exploited. We therefore do not plan on providing updates for this issue.


(Log in to post comments)

RHEL apache builds not affected

Posted Jul 29, 2006 17:29 UTC (Sat) by havoc (guest, #2261) [Link]

thank you!

RHEL apache builds not affected

Posted Jul 31, 2006 18:41 UTC (Mon) by JoeBuck (subscriber, #2330) [Link]

I hope that LWN will include pointers to information of this kind in the Security section when updates from other distros for this bug are announced; otherwise it will look like some distros aren't addressing the issue.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds