New httpd packages are available for Slackware 12.0, 12.1, 12.2, 13.0, and -current to fix security issues.
mod_ssl: A partial fix for the TLS renegotiation prefix injection attack by rejecting any client-initiated renegotiations.
mod_proxy_ajp: Respond with HTTP_BAD_REQUEST when the body is not sent when request headers indicate a request body is incoming; not a case of HTTP_INTERNAL_SERVER_ERROR.
mod_isapi: Do not unload an isapi .dll module until the request processing is completed, avoiding orphaned callback pointers. [This is the most serious flaw, but does not affect Linux systems]
Here are the details from the Slackware 13.0 ChangeLog: +--------------------------+ patches/packages/httpd-2.2.15-i486-1_slack13.0.txz: Upgraded. This update addresses a few security issues. mod_ssl: A partial fix for the TLS renegotiation prefix injection attack by rejecting any client-initiated renegotiations. mod_proxy_ajp: Respond with HTTP_BAD_REQUEST when the body is not sent when request headers indicate a request body is incoming; not a case of HTTP_INTERNAL_SERVER_ERROR. mod_isapi: Do not unload an isapi .dll module until the request processing is completed, avoiding orphaned callback pointers. [This is the most serious flaw, but does not affect Linux systems] For more information, see: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0408 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0425 (* Security fix *) +--------------------------+
Where to find the new packages: +-----------------------------+
HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com.
Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating additional FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you.
Upgrade the package as root: # upgradepkg httpd-2.2.15-x86_64-1_slack13.0.txz
Then, restart apache httpd: # sh /etc/rc.d/rc.httpd stop # sh /etc/rc.d/rc.httpd start
Note that using the "restart" option might not work, as the parent httpd process continues to run and may be unable to load the new httpd modules. Therefore, using "stop" and then "start" is recommended.
+------------------------------------------------------------------------+ | To leave the slackware-security mailing list: | +------------------------------------------------------------------------+ | Send an email to [email protected] with this text in the body of | | the email message: | | | | unsubscribe slackware-security | | | | You will get a confirmation message back containing instructions to | | complete the process. Please do not reply to this email address. | +------------------------------------------------------------------------+ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux)
09.06.2018 Panda Security объявляет о проведении акции «Бесплатный переход на версию 2010» При покупке любого продукта Panda Security для домашних пользователей до 1 августа 2009 года Вы получаете бесплатный переход на версии 2010 года.05.06.2018 Corporate News: Kaspersky Internet Security 2010: New Class of Internet Protection for Home and Small Office Users Kaspersky Lab announces the release of Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010, the new generation of Kaspersky Lab products based on the very latest developments in security technologies with the most comprehensive protection.24.06.2018 Corporate News: Kaspersky Lab releases Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Synergy between innovative technologies and intuitive interface brings system protection to a completely new level26.08.2018 CVE-2010-5092 The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a database.27.11.2018 Kaspersky Internet Security 2010 wins a dynamic test conducted by the Anti-Malware Test Lab Kaspersky Lab announces Kaspersky Internet Security 2010 has received the Gold Zero-Day Protection Award from the Anti-Malware Test Lab14.12.2018 Kaspersky Lab and the VimpelCom Group announce the launch of an online subscription service Kaspersky Lab and the VimpelCom Group announce the launch of an online subscription service for the new Kaspersky Lab products Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 201022.12.2018 Kaspersky Internet Security 2010 named 'Best Buy' by Computer Shopper Kaspersky Lab announces that the UK magazine Computer Shopper has awarded Kaspersky Internet Security 2010 its 'Best Buy' rating for an antivirus solution23.12.2018 Kaspersky Internet Security 2010 sweeps the competition aside in comparative testing carried out by the leading European IT magazine Computer Bild Kaspersky Lab announces that Kaspersky Internet Security 2010 outperformed all seven of its rivals in comparative testing carried out by the leading IT publication in Europe, Computer Bild29.12.2018 Kaspersky Internet Security 2010 ranks among leaders of ‘Real World’ test conducted by AV-Test laboratory Kaspersky Lab announces that Kaspersky Internet Security 2010 has demonstrated exceptionally high levels of protection in testing carried out by the respected German laboratory AV-Test as part of their Real World trial.12.01.2018 Фишеры освоили Android Google тихо удалил из Android Market целую серию приложений для онлайн-банкинга по подозрению в фишинге. Далее
Нет комментариев. Почему бы Вам не оставить свой?
Вы не можете отправить комментарий анонимно, пожалуйста зарегистрируйтесь.