|
From: Kurt Lieber <klieber@gentoo.org>
Date: Thu Jul 22 2004 - 09:23:10 EDT
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
A bug in mod_ssl may allow a remote attacker to execute arbitrary code
Background
mod_ssl provides Secure Sockets Layer encryption and authentication to
Affected packages
-------------------------------------------------------------------
Description
A bug in ssl_engine_ext.c makes mod_ssl vulnerable to a ssl_log()
Impact
Given the right server configuration, an attacker could execute code as
Workaround
A server should not be vulnerable if it is not using both mod_ssl and
Resolution
All mod_ssl users should upgrade to the latest version:
# emerge sync
# emerge -pv ">=net-www/mod_ssl-2.8.19"
References
[ 1 ] mod_ssl Announcement
Availability
This GLSA and any updates to it are available for viewing at
http://security.gentoo.org/glsa/glsa-200407-18.xml
Concerns?
Security is a primary focus of Gentoo Linux and ensuring the
License
Copyright 2004 Gentoo Foundation, Inc; referenced text
The contents of this document are licensed under the
http://creativecommons.org/licenses/by-sa/1.0
_______________________________________________
This archive was generated by hypermail 2.1.8 : Thu Jul 22 2004 - 11:13:08 EDT |
Custom Search
|