Linux.com

Home DistributionCentral Linux Security SUSE Security Announcement 2009:050: Apache and libapr1 security update

SUSE Security Announcement 2009:050: Apache and libapr1 security update


The Apache web server was updated to fix various security issues:

  • the option IncludesNOEXEC could be bypassed via .htaccess (CVE-2009-1195)
  • mod_proxy could run into an infinite loop when used as reverse proxy (CVE-2009-1890)
  • mod_deflate continued to compress large files even after a network connection was closed, causing mod_deflate to consume large amounts of CPU (CVE-2009-1891)
  • The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command. (CVE-2009-3094)
  • access restriction bypass in mod_proxy_ftp module (CVE-2009-3095)...
Read More

Comments (0)Add Comment

Write comment
You must be logged in to post a comment. Please register if you do not have an account yet.

busy
 
Become a Linux Foundation Member

Who we are ?

The Linux Foundation is a non-profit consortium dedicated to the growth of Linux.

More About the foundation...

Frequent Questions

Join / Members / Staff / Board