Oval Definition:oval:com.redhat.rhsa:def:20050608
Revision Date:2005-09-06Version:502
Title:RHSA-2005:608: httpd security update (Important)
Description:The Apache HTTP Server is a popular and freely-available Web server.

A flaw was discovered in mod_ssl's handling of the "SSLVerifyClient" directive. This flaw occurs if a virtual host is configured using "SSLVerifyClient optional" and a directive "SSLVerifyClient required" is set for a specific location. For servers configured in this fashion, an attacker may be able to access resources that should otherwise be protected, by not supplying a client certificate when connecting. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-2700 to this issue.

A flaw was discovered in Apache httpd where the byterange filter would buffer certain responses into memory. If a server has a dynamic resource such as a CGI script or PHP script that generates a large amount of data, an attacker could send carefully crafted requests in order to consume resources, potentially leading to a Denial of Service. (CAN-2005-2728)

Users of Apache httpd should update to these errata packages that contain backported patches to correct these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-2700
CVE-2005-2728
RHSA-2005:608-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • httpd-devel is earlier than 0:2.0.46-46.3.ent
  • AND httpd-devel is signed with Red Hat master key
  • mod_ssl is earlier than 0:2.0.46-46.3.ent
  • AND mod_ssl is signed with Red Hat master key
  • httpd is earlier than 0:2.0.46-46.3.ent
  • AND httpd is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • httpd-manual is earlier than 0:2.0.52-12.2.ent
  • AND httpd-manual is signed with Red Hat master key
  • httpd-suexec is earlier than 0:2.0.52-12.2.ent
  • AND httpd-suexec is signed with Red Hat master key
  • httpd-devel is earlier than 0:2.0.52-12.2.ent
  • AND httpd-devel is signed with Red Hat master key
  • mod_ssl is earlier than 0:2.0.52-12.2.ent
  • AND mod_ssl is signed with Red Hat master key
  • httpd is earlier than 0:2.0.52-12.2.ent
  • AND httpd is signed with Red Hat master key
  • BACK