|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2004-0942: Apache2 DoS | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Major | ||
| Priority: | P3 - Medium | CC: | security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2004-0942: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: | patchinfo files for 8.1, 8.2, 9.0, 9.1, 9.2 and SLES9 | ||
|
Description
Ludwig Nussel
2004-11-05 17:46:49 UTC
Fixed in 2.0.53-dev, patch available in 2.0 CVS: http://cvs.apache.org/viewcvs.cgi/httpd-2.0/server/protocol.c?r1=1.158&r2=1.159 Packages submitted to autobuild: /work/SRC/old-versions/8.1/all/apache2 -> /work/src/done/8.1 /work/SRC/old-versions/8.2/all/apache2 -> /work/src/done/8.2 /work/SRC/old-versions/9.0/all/apache2 -> /work/src/done/9.0 /work/SRC/old-versions/9.1/BETA/all/apache2 -> /work/src/done/SLES9-SP1 /work/SRC/old-versions/9.1/SLES/all/apache2 -> /work/src/done/9.1 /work/SRC/old-versions/9.2/all/apache2 -> /work/src/done/9.2 plus STABLE. ------------------------------------------------------------------- Mon Nov 8 19:18:52 CET 2004 - poeml@suse.de - security fix [CAN-2004-0942 (cve.mitre.org)]: Fix for memory consumption DoS [#47967] - security fix [CAN-2004-0885 (cve.mitre.org)]: fix SSLCipherSuite bypass in mod_ssl [#47117] ------------------------------------------------------------------- Patchinfos? I'll attach and submit them shortly. thanks. /me cancels context switch ;) Created attachment 25920 [details]
patchinfo files for 8.1, 8.2, 9.0, 9.1, 9.2 and SLES9
poeml@aust ~/tmp % tar tvzf patchinfos-apache2.tar.gz
drwxr-xr-x poeml/suse 0 2004-11-09 16:18:48 patchinfos-apache2/
-rw-r--r-- poeml/suse 1071 2004-11-09 16:17:27
patchinfos-apache2/patchinfo.apache2.box.81
-rw-r--r-- poeml/suse 1070 2004-11-09 16:17:32
patchinfos-apache2/patchinfo.apache2.box.82
-rw-r--r-- poeml/suse 1098 2004-11-09 16:17:45
patchinfos-apache2/patchinfo.apache2.box.90
-rw-r--r-- poeml/suse 1066 2004-11-09 16:17:51
patchinfos-apache2/patchinfo.apache2.box.91
-rw-r--r-- poeml/suse 1066 2004-11-09 16:18:21
patchinfos-apache2/patchinfo.apache2.box.92
-rw-r--r-- poeml/suse 839 2004-11-09 16:18:48
patchinfos-apache2/patchinfo.apache2.sles
DESCRIPTION:
An issue allowing a remote Denial of Service attack has been fixed (the request
field length limit was not enforced for certain malicious requests). A
vulnerability in the mod_ssl module has been fixed (bypass of the
"SSLCipherSuite" directive, when configured in directory or location context).
CAN-2004-0942 and CAN-2004-0885 have been assigned to these issues.
DESCRIPTION_DE:
Bei bestimmten Requests wurden Beschraenkungen von zu langen Kopfzeilen nicht
angewendet, was zu entsprechendem Speicherverbrauch des Servers fuehren konnte
und damit entfernten Angreifern einen Denial of Service-Angriff erlaubte.
Aussedem wurde eine Schwachstelle im mod_ssl Modul behoben (Aushebeln der
"SSLCipherSuite"-Direktive, wenn sie im in einem Directory- oder Location
Kontext verwendet wurde). Die Kennungen CAN-2004-0942 und CAN-2004-0885 wurden
diesen Schwachstellen zugewiesen.
I assign to security-team for further processing approved CVE-2004-0942: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) |