Jump to content


This topic is now archived and is closed to further replies.


[[ red hat 6.2 - 8.0 and packaged apache ]]

Recommended Posts

those of you running red hat 6.2 - 8.0 who have not registered your system, this was mailed as of feb. 10:


Red Hat Network has determined that the following advisory is applicable to

one or more of the systems you have registered:


Complete information about this errata can be found at the following location:



Security Advisory - RHSA-2002:222-21



Updated apache, httpd, and mod_ssl packages available


Updated apache and httpd packages which fix a number of security issues are

now available for Red Hat Linux 6.2, 7, 7.1, 7.2, 7.3, and 8.0.



The Apache HTTP Web Server is a secure, efficient, and extensible web

server that provides HTTP services.


Buffer overflows in the ApacheBench support program (ab.c) in Apache

versions prior to 1.3.27, and Apache versions 2.x prior to 2.0.43, allow a

malicious Web server to cause a denial of service (DoS) and possibly

execute arbitrary code via a long response. The Common Vulnerabilities and

Exposures project has assigned the name CAN-2002-0843 to this issue.


Two cross-site scripting (XSS) vulnerabilities are present in the error

pages for the default \\\"404 Not Found\\\" error and for the error response

when a plain HTTP request is received on an SSL port. Both of these issues

are only exploitable if the \\\"UseCanonicalName\\\" setting has been changed to

\\\"Off\\\", and wildcard DNS is in use. These issues could allow remote

attackers to execute scripts as other webpage visitors, for instance, to

steal cookies. These issues affect versions of Apache 1.3 before 1.3.26,

versions of Apache 2.0 before 2.0.43, and versions of mod_ssl before

2.8.12. (CAN-2002-0840, CAN-2002-1157)


The shared memory scoreboard in the HTTP daemon for Apache 1.3, prior to

version 1.3.27, allows a user running as the \\\"apache\\\" UID to send a

SIGUSR1 signal to any process as root, resulting in a denial of service

(process kill) or other such behavior that would not normally be allowed.  

(CAN-2002-0839). Note that this issue does not affect Red Hat

Linux 8.0.


All users of the Apache HTTP Web Server are advised to upgrade to the

applicable errata packages. For Red Hat Linux 6.2, 7, 7.1, 7.2, and 7.3,

these packages include Apache version 1.3.27 which is not vulnerable to

these issues. For Red Hat Linux 8.0, the fixes have been back-ported and

applied to Apache version 2.0.40.


Note that the instructions in the \\\"Solution\\\" section of this errata contain

additional steps required to complete the upgrade process.







Taking Action


You may address the issues outlined in this advisory in two ways:


- select your server name by clicking on its name from the list

available at the following location, and then schedule an

errata update for it:



- run the Update Agent on each affected server.




Changing Notification Preferences


To enable/disable your Errata Alert preferences globally please log in to RHN

and navigate from \\\"Your RHN\\\" / \\\"Your Account\\\" to the \\\"Preferences\\\" tab.


URL: https://rhn.redhat.com/network/my_account/my_prefs.pxt


You can also enable/disable notification on a per system basis by selecting an

individual system from the \\\"Systems List\\\". From the individual system view

click the \\\"Details\\\" tab.




Affected Systems


According to our records, this errata may apply to one or more of the  

systems that you\'ve profiled with Red Hat Network. To see precisely which  

systems are affected, please go to:



The Red Hat Network Team

Share this post

Link to post
Share on other sites


Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.