|
|
|
|
|
|
|
| |
SSA-2010-067-01 httpd |
|
| This script is Copyright (C) 2010 Tenable Network Security, Inc. |
|
|
| Family | Slackware Local Security Checks |
| Nessus Plugin ID | 45007 (Slackware_SSA_2010-067-01.nasl) |
| Bugtraq ID |
|
| CVE ID | CVE-2009-3555 CVE-2010-0408 CVE-2010-0425
|
|
| Description: |
Synopsis :
The remote host is missing the SSA-2010-067-01 security update
Description :
New httpd packages are available for Slackware 12.0, 12.1, 12.2, 13.0,
and -current to fix security issues.
mod_ssl: A partial fix for the TLS renegotiation prefix injection attack
by rejecting any client-initiated renegotiations.
mod_proxy_ajp: Respond with HTTP_BAD_REQUEST when the body is not sent
when request headers indicate a request body is incoming
not a case of
HTTP_INTERNAL_SERVER_ERROR.
mod_isapi: Do not unload an isapi .dll module until the request processing
is completed, avoiding orphaned callback pointers.
[This is the most serious flaw, but does not affect Linux systems]
More details about these issues may be found in the Common
Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0408
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0425
Solution :
Update the packages that are referenced in the security advisory.
Risk factor :
Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
|
|
|
|
|
|