Oval Definition:oval:com.redhat.rhsa:def:20060619
Revision Date:2006-08-10Version:642
Title:RHSA-2006:0619: httpd security update (Moderate)
Description:The Apache HTTP Server is a popular Web server available for free.

  • A bug was found in Apache where an invalid Expect header sent to the server was returned to the user in an unescaped error message. This could allow an attacker to perform a cross-site scripting attack if a victim was tricked into connecting to a site and sending a carefully crafted Expect header. (CVE-2006-3918)

    While a web browser cannot be forced to send an arbitrary Expect header by a third-party attacker, it was recently discovered that certain versions of the Flash plugin can manipulate request headers. If users running such versions can be persuaded to load a web page with a malicious Flash applet, a cross-site scripting attack against the server may be possible.

    On Red Hat Enterprise Linux 3 and 4 systems, due to an unrelated issue in the handling of malformed Expect headers, the page produced by the cross-site scripting attack will only be returned after a timeout expires (2-5 minutes by default) if not first canceled by the user.

    Users of httpd should update to these erratum packages, which contain a backported patch to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2006-3918
    RHSA-2006:0619
    RHSA-2006:0619-01
    RHSA-2006:0619-01
    Platform(s):Red Hat Enterprise Linux 3
    Red Hat Enterprise Linux 4
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • httpd-devel is earlier than 0:2.0.46-61.ent
  • AND httpd-devel is signed with Red Hat master key
  • httpd is earlier than 0:2.0.46-61.ent
  • AND httpd is signed with Red Hat master key
  • mod_ssl is earlier than 1:2.0.46-61.ent
  • AND mod_ssl is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • httpd-suexec is earlier than 0:2.0.52-28.ent
  • AND httpd-suexec is signed with Red Hat master key
  • httpd is earlier than 0:2.0.52-28.ent
  • AND httpd is signed with Red Hat master key
  • httpd-manual is earlier than 0:2.0.52-28.ent
  • AND httpd-manual is signed with Red Hat master key
  • httpd-devel is earlier than 0:2.0.52-28.ent
  • AND httpd-devel is signed with Red Hat master key
  • mod_ssl is earlier than 1:2.0.52-28.ent
  • AND mod_ssl is signed with Red Hat master key
  • Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • httpd is earlier than 0:2.0.52-28.ent
  • AND httpd is signed with Red Hat redhatrelease2 key
  • httpd-devel is earlier than 0:2.0.52-28.ent
  • AND httpd-devel is signed with Red Hat redhatrelease2 key
  • httpd-manual is earlier than 0:2.0.52-28.ent
  • AND httpd-manual is signed with Red Hat redhatrelease2 key
  • httpd-suexec is earlier than 0:2.0.52-28.ent
  • AND httpd-suexec is signed with Red Hat redhatrelease2 key
  • mod_ssl is earlier than 1:2.0.52-28.ent
  • AND mod_ssl is signed with Red Hat redhatrelease2 key
  • BACK