LWN.net Logo

httpd: multiple vulnerabilities

Package(s):httpd CVE #(s):CVE-2008-0455 CVE-2008-0456
Created:January 17, 2013 Updated:February 12, 2013
Description:

From the Scientific Linux advisory:

Input sanitization flaws were found in the mod_negotiation module. A remote attacker able to upload or create files with arbitrary names in a directory that has the MultiViews options enabled, could use these flaws to conduct cross-site scripting and HTTP response splitting attacks against users visiting the site. (CVE-2008-0455, CVE-2008-0456)

Alerts:
Scientific Linux SL-http-20130116 2013-01-16
Fedora FEDORA-2013-1661 2013-02-12
Red Hat RHSA-2013:0512-02 2013-02-21
Oracle ELSA-2013-0512 2013-02-25
Scientific Linux SL-http-20130228 2013-02-28
CentOS CESA-2013:0512 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds