wwwoldi.ru

Главная | Actual Topics | Обратная связь | Guest Book | В избранное | Сделать домашней
Категории
 Безопасность
 Деньги в Сети
 Право в Сети
 Сети
 Видео
 Процессоры
 Платформа
 Antivirus & Firewall
Календарь

June, 2016
ПнВтСрЧтПтСбВс
12345
6789101112
13141516171819
20212223242526
27282930
Опросы
Какой антивирус Вы предпочитаете для защиты Вашего компьютера?

Kaspersky Anti-Virus
Trend Micro Internet Security
Dr.Web
Panda Antivirus
Eset NOD32 Antivirus
Norton Antivirus
AVG Anti-Virus
CA Anti-Virus
Антивирус Stop!
Avast!
Зачем казе баян?


Результаты
Другие опросы

Всего голосов: 90
Комментарии: 0
Ссылки

Архив Новостей
  June 2016 (21)
  May 2016 (36)
  April 2016 (43)
  March 2016 (52)
  February 2016 (53)
  January 2016 (52)
  December 2015 (58)
  November 2015 (57)
  October 2015 (53)
  September 2015 (50)
  August 2015 (56)
  July 2015 (59)
  June 2015 (63)
  May 2015 (16)
  April 2015 (13)
  March 2015 (34)
  February 2015 (46)
  January 2015 (1)
  December 2014 (3)
  September 2014 (16)
  August 2014 (17)
  July 2014 (18)
  June 2014 (17)
  May 2014 (16)
  April 2014 (18)
  March 2014 (17)
  February 2014 (20)
  January 2014 (14)
  December 2013 (68)
  November 2013 (91)
  October 2013 (100)
  September 2013 (102)
  August 2013 (93)
  July 2013 (88)
  June 2013 (88)
  May 2013 (97)
  April 2013 (113)
  March 2013 (105)
  February 2013 (96)
  January 2013 (96)
  December 2012 (98)
  November 2012 (100)
  October 2012 (118)
  September 2012 (102)
  August 2012 (108)
  July 2012 (104)
  June 2012 (107)
  May 2012 (146)
  April 2012 (213)
  March 2012 (238)
  February 2012 (223)
  January 2012 (168)
  December 2011 (219)
  November 2011 (256)
  October 2011 (263)
  September 2011 (231)
  August 2011 (201)
  July 2011 (211)
  June 2011 (218)
  May 2011 (221)
  April 2011 (251)
  March 2011 (231)
  February 2011 (197)
  January 2011 (220)
  December 2010 (271)
  November 2010 (250)
  October 2010 (245)
  September 2010 (268)
  August 2010 (263)
  July 2010 (262)
  June 2010 (286)
  May 2010 (250)
  April 2010 (274)
  March 2010 (318)
  February 2010 (259)
  January 2010 (259)
  December 2009 (305)
  November 2009 (50)
  June 2009 (459)
  May 2009 (550)
  April 2009 (532)
  March 2009 (510)
  February 2009 (512)
  January 2009 (451)
  December 2008 (428)
  November 2008 (169)
  October 2008 (602)
  September 2008 (496)
  August 2008 (406)
  July 2008 (47)
  June 2008 (42)
  May 2008 (23)
  April 2008 (20)
  March 2008 (21)
  February 2008 (17)
  January 2008 (16)
  December 2007 (13)
  November 2007 (8)
  October 2007 (8)
  September 2007 (5)
  August 2007 (6)
  July 2007 (8)
  June 2007 (5)
  May 2007 (4)
  April 2007 (10)
  March 2007 (5)
  February 2007 (7)
  January 2007 (7)
  December 2006 (11)
  November 2006 (6)
  October 2006 (5)
  September 2006 (3)
  August 2006 (3)
  July 2006 (6)
  June 2006 (1)
  May 2006 (9)
  April 2006 (5)
  March 2006 (5)
  February 2006 (1)
  January 2006 (4)
  December 2005 (5)
  November 2005 (7)
  October 2005 (3)
  September 2005 (3)
  August 2005 (1)
  July 2005 (4)
  June 2005 (3)
  May 2005 (1)
  April 2005 (3)
  March 2005 (4)
  February 2005 (2)
  January 2005 (2)
  December 2004 (2)
  November 2004 (3)
  October 2004 (2)
  August 2004 (1)
  July 2004 (2)
  June 2004 (2)
  May 2004 (3)
  March 2004 (1)
  February 2004 (1)
  January 2004 (1)
  December 2003 (3)
  November 2003 (1)
  October 2003 (2)
  September 2003 (2)
  August 2003 (1)
  June 2003 (1)
  May 2003 (1)
  April 2003 (3)
  March 2003 (1)
  February 2003 (3)
  December 2002 (1)
  October 2002 (4)
  February 2002 (1)
  January 2002 (2)
  December 2001 (1)
  November 2001 (1)
  September 2001 (2)
  August 2001 (1)
  May 2001 (1)
  March 2001 (7)
  February 2001 (1)
  January 2001 (1)
  July 2000 (1)
  March 2000 (1)
  January 2000 (2)
  October 1999 (1)

2010-03-08 - [slackware-security] httpd (SSA:2010-067-01)

Безопасность -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[slackware-security]  httpd (SSA:2010-067-01)

New httpd packages are available for Slackware 12.0, 12.1, 12.2, 13.0,
and -current to fix security issues.

mod_ssl: A partial fix for the TLS renegotiation prefix injection attack
  by rejecting any client-initiated renegotiations.

mod_proxy_ajp: Respond with HTTP_BAD_REQUEST when the body is not sent
  when request headers indicate a request body is incoming; not a case of
  HTTP_INTERNAL_SERVER_ERROR.

mod_isapi: Do not unload an isapi .dll module until the request processing
  is completed, avoiding orphaned callback pointers.
  [This is the most serious flaw, but does not affect Linux systems]

More details about these issues may be found in the Common
Vulnerabilities and Exposures (CVE) database:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0408
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0425


Here are the details from the Slackware 13.0 ChangeLog:
+--------------------------+
patches/packages/httpd-2.2.15-i486-1_slack13.0.txz:  Upgraded.
  This update addresses a few security issues.
  mod_ssl: A partial fix for the TLS renegotiation prefix injection attack
    by rejecting any client-initiated renegotiations.
  mod_proxy_ajp: Respond with HTTP_BAD_REQUEST when the body is not sent
    when request headers indicate a request body is incoming; not a case of
    HTTP_INTERNAL_SERVER_ERROR.
  mod_isapi: Do not unload an isapi .dll module until the request processing
    is completed, avoiding orphaned callback pointers.
    [This is the most serious flaw, but does not affect Linux systems]
  For more information, see:
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0408
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0425
  (* Security fix *)
+--------------------------+


Where to find the new packages:
+-----------------------------+

HINT:  Getting slow download speeds from ftp.slackware.com?
Give slackware.osuosl.org a try.  This is another primary FTP site
for Slackware that can be considerably faster than downloading
directly from ftp.slackware.com.

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating additional FTP and rsync hosting
to the Slackware project!  :-)

Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 12.0:
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/httpd-2.2.15-i486-1_slack12.0.tgz

Updated package for Slackware 12.1:
ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/httpd-2.2.15-i486-1_slack12.1.tgz

Updated package for Slackware 12.2:
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/httpd-2.2.15-i486-1_slack12.2.tgz

Updated package for Slackware 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/httpd-2.2.15-i486-1_slack13.0.txz

Updated package for Slackware x86_64 13.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/httpd-2.2.15-x86_64-1_slack13.0.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/httpd-2.2.15-i486-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/httpd-2.2.15-x86_64-1.txz


MD5 signatures:
+-------------+

Slackware 12.0 package:
16cec75d359c8ce94cf363a8ba5ca5aa  httpd-2.2.15-i486-1_slack12.0.tgz

Slackware 12.1 package:
1dedbfa17735c9d61ab552b6d6a4c452  httpd-2.2.15-i486-1_slack12.1.tgz

Slackware 12.2 package:
fa725cd74a40c4e647f6dbc0af7760fc  httpd-2.2.15-i486-1_slack12.2.tgz

Slackware 13.0 package:
768cb6af77170bb51c9303dc87b17138  httpd-2.2.15-i486-1_slack13.0.txz

Slackware x86_64 13.0 package:
96be84be6907b5f370a815c874bb7a80  httpd-2.2.15-x86_64-1_slack13.0.txz

Slackware -current package:
6aac4a1e47c8292634cfcfcadfd81a1c  httpd-2.2.15-i486-1.txz

Slackware x86_64 -current package:
ecdc430b9b3901e8138cf83a7e41fe09  httpd-2.2.15-x86_64-1.txz


Installation instructions:
+------------------------+

Upgrade the package as root:
# upgradepkg httpd-2.2.15-x86_64-1_slack13.0.txz

Then, restart apache httpd:
# sh /etc/rc.d/rc.httpd stop
# sh /etc/rc.d/rc.httpd start

Note that using the "restart" option might not work, as the parent httpd
process continues to run and may be unable to load the new httpd modules.
Therefore, using "stop" and then "start" is recommended.


+-----+

Slackware Linux Security Team
http://slackware.com/gpg-key
[email protected]

+------------------------------------------------------------------------+
| To leave the slackware-security mailing list:                          |
+------------------------------------------------------------------------+
| Send an email to [email protected] with this text in the body of |
| the email message:                                                     |
|                                                                        |
|   unsubscribe slackware-security                                       |
|                                                                        |
| You will get a confirmation message back containing instructions to    |
| complete the process.  Please do not reply to this email address.      |
+------------------------------------------------------------------------+
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iEYEARECAAYFAkuVZxUACgkQakRjwEAQIjO2ewCgi1A16gKwP2X96dqThNYjOvOn
PSUAn1KM4R2O32/TRdR7ZECr5HxoBzsj
=4OSZ
-----END PGP SIGNATURE-----






  


Разместил: SecurityLab.ru - Уведомления | Дата: 09.03.2018 | Прочитано: 375 | Раздел: Безопасность   

Рейтинг статьи

Средняя оценка: 0.00/0Средняя оценка: 0Всего голосов:0



Смотрите также связанные темы

09.06.2018 Panda Security объявляет о проведении акции «Бесплатный переход на версию 2010»
При покупке любого продукта Panda Security для домашних пользователей до 1 августа 2009 года Вы получаете бесплатный переход на версии 2010 года.
05.06.2018 Corporate News: Kaspersky Internet Security 2010: New Class of Internet Protection for Home and Small Office Users
Kaspersky Lab announces the release of Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010, the new generation of Kaspersky Lab products based on the very latest developments in security technologies with the most comprehensive protection.
24.06.2018 Corporate News: Kaspersky Lab releases Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010
Synergy between innovative technologies and intuitive interface brings system protection to a completely new level
26.08.2018 CVE-2010-5092
The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a database.
27.11.2018 Kaspersky Internet Security 2010 wins a dynamic test conducted by the Anti-Malware Test Lab
Kaspersky Lab announces Kaspersky Internet Security 2010 has received the Gold Zero-Day Protection Award from the Anti-Malware Test Lab
14.12.2018 Kaspersky Lab and the VimpelCom Group announce the launch of an online subscription service
Kaspersky Lab and the VimpelCom Group announce the launch of an online subscription service for the new Kaspersky Lab products Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010
22.12.2018 Kaspersky Internet Security 2010 named 'Best Buy' by Computer Shopper
Kaspersky Lab announces that the UK magazine Computer Shopper has awarded Kaspersky Internet Security 2010 its 'Best Buy' rating for an antivirus solution
23.12.2018 Kaspersky Internet Security 2010 sweeps the competition aside in comparative testing carried out by the leading European IT magazine Computer Bild
Kaspersky Lab announces that Kaspersky Internet Security 2010 outperformed all seven of its rivals in comparative testing carried out by the leading IT publication in Europe, Computer Bild
29.12.2018 Kaspersky Internet Security 2010 ranks among leaders of ‘Real World’ test conducted by AV-Test laboratory
Kaspersky Lab announces that Kaspersky Internet Security 2010 has demonstrated exceptionally high levels of protection in testing carried out by the respected German laboratory AV-Test as part of their Real World trial.
12.01.2018 Фишеры освоили Android
Google тихо удалил из Android Market целую серию приложений для онлайн-банкинга по подозрению в фишинге. Далее
Нет комментариев. Почему бы Вам не оставить свой?
Вы не можете отправить комментарий анонимно, пожалуйста зарегистрируйтесь.
Google Search
Google

Web

Топ Новостей
1: MS14-011: Vulnerability in VBScript Scripting Engine Could Allow Remote Code Execution (2928390)
Hot NEWS!
Просмотров - 521


2: Компрометация системы в IBM Content Collector
Просмотров - 416

3: Отказ в обслуживании в FFmpeg
Просмотров - 401

4: Безопасность IOS-приложений (часть 16) – динамический анализ IOS-приложений при помощи iNalyzer
Просмотров - 291

5: Хакер обманом заполучил имя пользователя Twitter стоимостью в тыс.
Просмотров - 278

6: Межсайтовый скриптинг в Vanilla Forums
Просмотров - 270

7: Обновление PowerLoader’a для 64-разрядных систем на основе утечек кода новых эксплоитов
Просмотров - 256

8: Отчет с 17-ой встречи DEFCON группы
Просмотров - 247

9: Hetman File Repair
Просмотров - 242

10: AntiSnooper - Privacy Protection
Просмотров - 228

11: MS14-020: Vulnerability in Microsoft Publisher Could Allow Remote Code Execution (2950145)
Просмотров - 222

12: Безопасность IOS-приложений (часть 26) – Патчинг приложений при помощи IDA Pro и Hex Fiend
Просмотров - 216

13: MS14-004: Vulnerability in Microsoft Dynamics AX Could Allow Denial of Service (2880826)
Просмотров - 213

14: Множественные уязвимости в Oracle Java SE Embedded
Просмотров - 212

15: Межсайтовый скриптинг в IBM InfoSphere Guardium
Просмотров - 211

16: Microsoft отказалась раскрывать клиентские данные, хранящиеся за рубежом
Просмотров - 201

17: Компрометация системы в продуктах F5
Просмотров - 198

18: Межсайтовый скриптинг в UNIT4 Prosoft HRMS
Просмотров - 198

19: CVE-2014-2223
Просмотров - 196

20: CVE-2014-3352
Просмотров - 193

Google 120X240
Ссылки

Главная | Actual Topics | Статьи | Обратная связь | printZ | Guest Book
2019 © Все права защищены. Карта сайта



.