- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200304-01
- - ---------------------------------------------------------------------
FIXED VERSION : >=2.0.45
- - ---------------------------------------------------------------------
- From advisory:
"Remote exploitation of a memory leak in the Apache HTTP Server causes the
daemon to over utilize system resources on an affected system. The problem
is HTTP Server's handling of large chunks of consecutive linefeed
characters. The web server allocates an eighty-byte buffer for each
linefeed character without specifying an upper limit for allocation.
Consequently, an attacker can remotely exhaust system resources by
generating many requests containing these characters."
Read the full advisory at:
/us-en
SOLUTION
It is recommended that all Gentoo Linux users who are running
net-www/apache version 2 upgrade to apache-2.0.45 as follows:
emerge sync
emerge \=net-www/apache...Read the Full Advisory
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.