8624176 2002-06-19 14:22 +0200 /56 rader/ Wichert Akkerman <wichert@wiggy.net> Sänt av: joel@lysator.liu.se Importerad: 2002-06-19 22:32 av Brevbäraren Extern mottagare: debian-security-announce@lists.debian.org Externa svar till: security@debian.org Mottagare: Bugtraq (import) <22734> Ärende: [SECURITY] [DSA-131-2] Apache chunk handling vulnerability, update ------------------------------------------------------------ From: Wichert Akkerman <wichert@wiggy.net> To: debian-security-announce@lists.debian.org Message-ID: <20020619122225.GA2245@wiggy.net> -----BEGIN PGP SIGNED MESSAGE----- - ------------------------------------------------------------------------ Debian Security Advisory DSA-131-2 security@debian.org http://www.debian.org/security/ Wichert Akkerman June 19, 2002 - ------------------------------------------------------------------------ Package : apache Problem type : remote DoS / exploit Debian-specific: no CVE name : CAN-2002-0392 CERT advisory : VU#944335 The DSA-131-1 advisory for the Apache chunk handling vulnerability contained an error and was missing some essential information: * The upstream fix was for the 1.3 series was made in version 1.3.26, not version 1.3.16 as the advisory incorrectly stated * The package upgrade does not restart the apache server automatically, this will have to be done manually. Please make sure your configuration is correct ("apachectl configtest" will verify that for you) and restart it using "/etc/init.d/apache restart" For details on the vulnerability and the updated packages please see the original advisory or visit the Debian security web-pages (available at http://www.debian.org/security/). - -- - ---------------------------------------------------------------------------- apt-get: deb http://security.debian.org/ stable/updates main dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQB1AwUBPRB3fajZR/ntlUftAQFOVwMAt2VnafXPwdKgXNfaAU/mHFa3jSOIMgZv 08v2Ul4LP1eD5FvqGl3lqmxSc9bEOwrCbUG8LWO+Jbl/YNjSuBofi5DzLGhIlD/q UYVQn9Zvnr71d43qJ2Zwy9bltxl67Y8R =8J1R -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to debian-security-announce-request@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org (8624176) /Wichert Akkerman <wichert@wiggy.net>/(Ombruten)