Oval Definition:oval:org.mitre.oval:def:13835
Revision Date:2014-06-30Version:20
Title:USN-731-1 -- apache2 vulnerabilities
Description:It was discovered that Apache did not sanitize the method specifier header from an HTTP request when it is returned in an error message, which could result in browsers becoming vulnerable to cross-site scripting attacks when processing the output. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. This issue only affected Ubuntu 6.06 LTS and 7.10. It was discovered that Apache was vulnerable to a cross-site request forgery in the mod_proxy_balancer balancer manager. If an Apache administrator were tricked into clicking a link on a specially crafted web page, an attacker could trigger commands that could modify the balancer manager configuration. This issue only affected Ubuntu 7.10 and 8.04 LTS. It was discovered that Apache had a memory leak when using mod_ssl with compression. A remote attacker could exploit this to exhaust server memory, leading to a denial of service. This issue only affected Ubuntu 7.10. It was discovered that in certain conditions, Apache did not specify a default character set when returning certain error messages containing UTF-7 encoded data, which could result in browsers becoming vulnerable to cross-site scripting attacks when processing the output. This issue only affected Ubuntu 6.06 LTS and 7.10. It was discovered that when configured as a proxy server, Apache did not limit the number of forwarded interim responses. A malicious remote server could send a large number of interim responses and cause a denial of service via memory exhaustion. It was discovered that mod_proxy_ftp did not sanitize wildcard pathnames when they are returned in directory listings, which could result in browsers becoming vulnerable to cross-site scripting attacks when processing the output
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-6203
CVE-2007-6420
CVE-2008-1678
CVE-2008-2168
CVE-2008-2364
CVE-2008-2939
USN-731-1
USN-731-1
Platform(s):Ubuntu 6.06
Ubuntu 7.10
Ubuntu 8.04
Product(s):apache2
Definition Synopsis
  • Release section
  • Ubuntu 7.10 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • apache2-mpm-perchild DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR apache2-doc DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR apache2-src DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR apache2 DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • apache2-utils DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR apache2-mpm-worker DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR apache2.2-common DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR apache2-mpm-prefork DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR apache2-threaded-dev DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR apache2-mpm-event DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR apache2-prefork-dev DPKG is earlier than 2.2.4-3ubuntu0.2
  • OR Release section
  • Ubuntu 8.04 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • apache2-mpm-perchild DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR apache2-doc DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR apache2-src DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR apache2 DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is amd64
  • OR Installed architecture is i386
  • OR Installed architecture is powerpc
  • OR Installed architecture is sparc
  • OR Installed architecture is lpia
  • AND Packages section
  • apache2-utils DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR apache2-mpm-worker DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR apache2.2-common DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR apache2-mpm-prefork DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR apache2-threaded-dev DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR apache2-mpm-event DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR apache2-prefork-dev DPKG is earlier than 2.2.8-1ubuntu0.4
  • OR Release section
  • Ubuntu 6.06 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND apache2-doc DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR Architecture depended section
  • Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is powerpc
  • OR Installed architecture is amd64
  • OR Installed architecture is i386
  • AND Packages section
  • libapr0 DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR apache2-utils DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR apache2-mpm-worker DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR apache2-mpm-perchild DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR apache2-common DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR libapr0-dev DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR apache2 DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR apache2-threaded-dev DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR apache2-mpm-prefork DPKG is earlier than 2.0.55-4ubuntu2.4
  • OR apache2-prefork-dev DPKG is earlier than 2.0.55-4ubuntu2.4
  • BACK