Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: 2010-118: Apache: Denial of Service
Posted by Benjamin D. Thomas
A vulnerability has been fixed in Apache, which can be exploited by malicious people to cause DoS.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2010-118 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2010-08-24
Severity: 3
Type: Remote
------------------------------------------------------------------------
Summary
======
A vulnerability has been fixed in Apache, which can be exploited by
malicious people to cause DoS.
Description
==========
CVE-2010-1452:
The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server
2.2.x before 2.2.16 allow remote attackers to cause a denial of service
(process crash) via a request that lacks a path.
Affected packages:
Pardus 2009:
apache, all before 2.2.16-37-12
Resolution
=========
There are update(s) for apache. You can update them via Package Manager
or with a single command from console:
pisi up apache
References
=========
* http://bugs.pardus.org.tr/show_bug.cgi?id945
* http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1452
------------------------------------------------------------------------