Oval Definition:oval:org.mitre.oval:def:29317
Revision Date:2015-08-17Version:9
Title:RHSA-2009:1579 -- httpd security update (Moderate)
Description:Updated httpd packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 3 and 5.This update has been rated as having moderate security impact by the RedHat Security Response Team.The Apache HTTP Server is a popular Web server.A flaw was found in the way the TLS/SSL (Transport Layer Security/SecureSockets Layer) protocols handle session renegotiation. A man-in-the-middleattacker could use this flaw to prefix arbitrary plain text to a client'ssession (for example, an HTTPS connection to a website). This could forcethe server to process an attacker's request as if authenticated using thevictim's credentials. This update partially mitigates this flaw for SSLsessions to HTTP servers using mod_ssl by rejecting client-requestedrenegotiation. (CVE-2009-3555)
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2009:1579-CentOS 3
CESA-2009:1579-CentOS 5
CVE-2009-3094
CVE-2009-3095
CVE-2009-3555
RHSA-2009:1579
Platform(s):CentOS Linux 3
CentOS Linux 5
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 5
Product(s):httpd
Definition Synopsis
  • Red Hat Enterprise Linux 5 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • AND Packages match section
  • httpd-devel is earlier than 0:2.2.3-31.el5_4.2
  • OR httpd-manual is earlier than 0:2.2.3-31.el5_4.2
  • OR httpd is earlier than 0:2.2.3-31.el5_4.2
  • OR mod_ssl is earlier than 0:2.2.3-31.el5_4.2
  • Red Hat Enterprise Linux 3 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 3
  • AND Packages match section
  • httpd is earlier than 0:2.0.46-77.ent
  • OR httpd-devel is earlier than 0:2.0.46-77.ent
  • OR mod_ssl is earlier than 0:2.0.46-77.ent
  • CentOS Linux 5 release section
  • The operating system installed on the system is CentOS Linux 5.x
  • AND Packages match section
  • httpd is earlier than 0:2.2.3-31.el5.centos.2
  • OR httpd-devel is earlier than 0:2.2.3-31.el5.centos.2
  • OR httpd-manual is earlier than 0:2.2.3-31.el5.centos.2
  • OR mod_ssl is earlier than 0:2.2.3-31.el5.centos.2
  • BACK