[PLDSA 54-1] New apache-mod_access_referer fix denial of service

Krzysiek Taraszka dzimi at pld.org.pl
Sat May 3 15:46:39 CEST 2003


- --------------------------------------------------------------------------
PLD Security Advisory PLDSA 54-1		       security at pld.org.pl
http://www.pld.org.pl/security/                          PLD Security Team
16 April 2003				http://www.pld.org.pl/security/faq
- --------------------------------------------------------------------------

Package        : prior to apache-mod_access_referer-1.0.2-5
Vulnerability  : denial of service
Problem-Type   : remote
PLD-specific   : no

apache-mod_access_referer is an module for the Apache HTTP Server that 
provides access control based on "Referer" HTTP header content.
Niels Heinen discovered a security problem in apache-mod_access_referer.
A vulnerability may possibly be used in denial of service attacks.

The above problems have been fixed in version 1.0.2-6 for the
current stable distribution (ra).

We recommend that you upgrade your apache-mod_access_referer packages.

wget -c url
	will fetch the file for you
rpm -Uhv file(s)*.rpm
        will upgrade the referenced file.

If you are using "poldek" - the package manager, use the line as given below
for upgrade packages

poldek --update
        will update the internal database
poldek --upgrade 'apache-mod_access_referer*'
        will install corrected packages

If you are using "apt" - the package manager, use the line as given below
for upgrade packages

apt-get update
        will update the internal database
apt-get upgrade 'apache-mod_access_referer*'
        will install corrected packages

PLD Linux 1.0 alias ra
- --------------------

  Source archives:

ftp://ftp.pld.org.pl/dists/ra/updates/security/SRPMS/apache-mod_access_referer-1.0.2-6.src.rpm
       MD5 checksum: 1a25c36f660adea409edf415e10d9181

  I386 Architecture components:

ftp://ftp.pld.org.pl/dists/ra/updates/security/i386/apache-mod_access_referer-1.0.2-6.i386.rpm
       MD5 checksum: ff2f7f8edc7acd603ba31ca500b954ce


  I586 Architecture components:

ftp://ftp.pld.org.pl/dists/ra/updates/security/i586/apache-mod_access_referer-1.0.2-6.i586.rpm
       MD5 checksum: c83b597bd6dc1cfa59cf5c7f1f05241a


  I686 Architecture components:

ftp://ftp.pld.org.pl/dists/ra/updates/security/i686/apache-mod_access_referer-1.0.2-6.i686.rpm
       MD5 checksum: 089e917ed57cb706f5df5b2cddd68d40


  PowerPC Architecture components:

ftp://ftp.pld.org.pl/dists/ra/updates/security/ppc/apache-mod_access_referer-1.0.2-6.ppc.rpm
       MD5 checksum: 4ceeee010ec30b5409d385d33f91a01d


-
--------------------------------------------------------------------------------
-
If you are using poldek add this line to poldek.conf.
If you are using apt-get add this line to sources.list.

For i386 architecture
poldek:         source = ra-updates-security ftp://ftp.pld.org.pl/dists/ra/updates/security/i386/
apt-get:        rpm ftp://ftp.pld.org.pl/dists ra/apt/i386 base updates-security
For i586 architecture
poldek:         source = ra-updates-security ftp://ftp.pld.org.pl/dists/ra/updates/security/i586/
apt-get:        rpm ftp://ftp.pld.org.pl/dists ra/apt/i586 base updates-security
For i686 architecture
poldek:         source = ra-updates-security ftp://ftp.pld.org.pl/dists/ra/updates/security/i686/
apt-get:        rpm ftp://ftp.pld.org.pl/dists ra/apt/i686 base updates-security
For ppc architecture
poldek:         source = ra-updates-security ftp://ftp.pld.org.pl/dists/ra/updates/security/ppc/
apt-get:        rpm ftp://ftp.pld.org.pl/dists ra/apt/ppc base updates-security



More information about the pld-security-announce mailing list