RHEL apache builds not affected
Posted Jul 29, 2006 17:20 UTC (Sat) by dowdle
Parent article: Apache update for a remote vulnerability
Recently added to Red Hat's Knowledgebase:
Is Red Hat Enterprise Linux vulnerable to the Apache mod_rewrite off-by-one vulnerability (CVE-2006-3747)?
This issue does not affect the version of Apache httpd as supplied with Red Hat Enterprise Linux 2.1 as it does not contain the vulnerable code.
The ability to exploit this issue is dependent on the stack layout for a particular compiled version of mod_rewrite. If the compiler has added padding to the stack immediately after the buffer being overwritten, this issue can not be exploited, and Apache httpd will continue operating normally.
The Red Hat Security Response Team analyzed Red Hat Enterprise Linux 3 and Red Hat Enterprise Linux 4 binaries for all architectures as packaged by Red Hat and determined that these versions cannot be exploited. We therefore do not plan on providing updates for this issue.
to post comments)