Apache mod_ssl Denial Of Service Vulnerability
BID:11094
Info
Apache mod_ssl Denial Of Service Vulnerability
| Bugtraq ID: | 11094 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0748 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 02 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Francis Wai <[email protected]> reported this vulnerability to the vendor. |
| Vulnerable: |
Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Home Trustix Secure Linux 2.1 Trustix Secure Linux 2.0 Trustix Secure Enterprise Linux 2.0 Mandriva Linux Mandrake 10.0 AMD64 Mandriva Linux Mandrake 10.0 Mandriva Linux Mandrake 9.2 amd64 Mandriva Linux Mandrake 9.2 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 Gentoo Linux 1.4 Avaya S8700 R2.0.1 Avaya S8700 R2.0.0 Avaya S8500 R2.0.1 Avaya S8500 R2.0.0 Avaya S8300 R2.0.1 Avaya S8300 R2.0.0 Avaya Converged Communications Server 2.0 Apache Apache 2.0.50 Apache Apache 2.0.49 Apache Apache 2.0.48 Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.32 Apache Apache 2.0.28 Beta Apache Apache 2.0.28 Apache Apache 2.0 a9 Apache Apache 2.0 |
| Not Vulnerable: |
Apache Apache 2.0.51 |
Discussion
Apache mod_ssl Denial Of Service Vulnerability
Apache mod_ssl is reported susceptible to a denial of service vulnerability.
This issue presents itself during SSL connections to a vulnerable Apache server. The affected software may enter into an infinite loop in certain circumstances. This will consume CPU resources and potentially cause further connections to the affected server to fail.
All Apache versions from 2.0 through to 2.0.50 are reported vulnerable.
Update: Avaya has released an advisory identifying Avaya S8700/S8500/S8300 running CM 2.0 and later, and all versions of Avaya Converged Communication Server as vulnerable to this issue.
Apache mod_ssl is reported susceptible to a denial of service vulnerability.
This issue presents itself during SSL connections to a vulnerable Apache server. The affected software may enter into an infinite loop in certain circumstances. This will consume CPU resources and potentially cause further connections to the affected server to fail.
All Apache versions from 2.0 through to 2.0.50 are reported vulnerable.
Update: Avaya has released an advisory identifying Avaya S8700/S8500/S8300 running CM 2.0 and later, and all versions of Avaya Converged Communication Server as vulnerable to this issue.
Exploit / POC
Apache mod_ssl Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache mod_ssl Denial Of Service Vulnerability
Solution:
Turbolinux has released advisory TLSA-2005-01-13 along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
RedHat has released advisory RHSA-2004:349-10 addressing this, and other issues. Please see the referenced advisory for further information on obtaining fixes.
SuSE has released advisory SUSE-SA:2004:030 and fixes that eliminate this vulnerability. Please see the referenced advisory.
Mandrake Linux has released an advisory (MDKSA-2004:096) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Trustix Secure Linux has released an advisory (TSLSA-2004-0047) along with fixes dealing with this, and other issues. Please see the referenced advisory for further information.
Gentoo Linux has released advisory GLSA 200409-21 to address this, and other issues. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following with superuser privileges:
emerge sync
emerge -pv ">=net-www/apache-2.0.51"
emerge ">=net-www/apache-2.0.51"
emerge -pv ">=net-www/mod_dav-1.0.3-r2"
emerge ">=net-www/mod_dav-1.0.3-r2"
Conectiva Linux has released advisory CLA-2004:868 along with fixes to address this, and other issues. Please see the referenced advisory for further information.
Red Hat Fedora has released an advisory (FEDORA-2004-313) along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
Apache has released version 2.0.51 to address this, and other issues:
HP has released an advisory (HPSBUX01090) to address various issues affecting HP-UX running Apache and PHP. Please see the referenced advisory for more information.
Apple has released an advisory (APPLE-SA-2004-12-02) dealing with this and other issues. Please see the referenced advisory for more information.
Apache Apache 2.0
Apache Apache 2.0 a9
Apache Apache 2.0.28
Apache Apache 2.0.28 Beta
Apache Apache 2.0.32
Apache Apache 2.0.35
Apache Apache 2.0.36
Apache Apache 2.0.37
Apache Apache 2.0.38
Apache Apache 2.0.39
Apache Apache 2.0.40
Apache Apache 2.0.41
Apache Apache 2.0.42
Apache Apache 2.0.43
Apache Apache 2.0.44
Apache Apache 2.0.45
Apache Apache 2.0.46
Apache Apache 2.0.47
Apache Apache 2.0.48
Apache Apache 2.0.49
Apache Apache 2.0.50
Solution:
Turbolinux has released advisory TLSA-2005-01-13 along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
RedHat has released advisory RHSA-2004:349-10 addressing this, and other issues. Please see the referenced advisory for further information on obtaining fixes.
SuSE has released advisory SUSE-SA:2004:030 and fixes that eliminate this vulnerability. Please see the referenced advisory.
Mandrake Linux has released an advisory (MDKSA-2004:096) along with fixes dealing with this issue. Please see the referenced advisory for more information.
Trustix Secure Linux has released an advisory (TSLSA-2004-0047) along with fixes dealing with this, and other issues. Please see the referenced advisory for further information.
Gentoo Linux has released advisory GLSA 200409-21 to address this, and other issues. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following with superuser privileges:
emerge sync
emerge -pv ">=net-www/apache-2.0.51"
emerge ">=net-www/apache-2.0.51"
emerge -pv ">=net-www/mod_dav-1.0.3-r2"
emerge ">=net-www/mod_dav-1.0.3-r2"
Conectiva Linux has released advisory CLA-2004:868 along with fixes to address this, and other issues. Please see the referenced advisory for further information.
Red Hat Fedora has released an advisory (FEDORA-2004-313) along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
Apache has released version 2.0.51 to address this, and other issues:
HP has released an advisory (HPSBUX01090) to address various issues affecting HP-UX running Apache and PHP. Please see the referenced advisory for more information.
Apple has released an advisory (APPLE-SA-2004-12-02) dealing with this and other issues. Please see the referenced advisory for more information.
Apache Apache 2.0
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0 a9
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.28
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.28 Beta
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.32
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.35
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.36
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.37
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.38
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.39
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.40
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz -
SuSE apache2-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/apache2-2.0.48-13 5.i586.patch.rpm -
SuSE apache2-prefork-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/apache2-prefork-2 .0.48-135.i586.patch.rpm -
SuSE apache2-worker-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/apache2-worker-2. 0.48-135.i586.patch.rpm -
SuSE apache2-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/apache2-2.0.48-13 5.i586.rpm -
SuSE apache2-prefork-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/apache2-prefork-2 .0.48-135.i586.rpm -
SuSE apache2-worker-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/apache2-worker-2. 0.48-135.i586.rpm
Apache Apache 2.0.41
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.42
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.43
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.44
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz -
Conectiva apache-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-2.0.45-28790U90_8cl. i386.rpm -
Conectiva apache-devel-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-devel-2.0.45-28790U9 0_8cl.i386.rpm -
Conectiva apache-doc-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-doc-2.0.45-28790U90_ 8cl.i386.rpm -
Conectiva apache-htpasswd-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-htpasswd-2.0.45-2879 0U90_8cl.i386.rpm -
Conectiva libapr-devel-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-2.0.45-28790U9 0_8cl.i386.rpm -
Conectiva libapr-devel-static-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-static-2.0.45- 28790U90_8cl.i386.rpm -
Conectiva libapr0-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr0-2.0.45-28790U90_8cl .i386.rpm -
Conectiva mod_auth_ldap-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_auth_ldap-2.0.45-28790U 90_8cl.i386.rpm -
Conectiva mod_dav-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_dav-2.0.45-28790U90_8cl .i386.rpm -
SuSE apache2-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/apache2-2.0.48-13 5.i586.patch.rpm -
SuSE apache2-prefork-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/apache2-prefork-2 .0.48-135.i586.patch.rpm -
SuSE apache2-worker-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/apache2-worker-2. 0.48-135.i586.patch.rpm -
SuSE libapr0-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/libapr0-2.0.48-13 5.i586.patch.rpm -
SuSE apache2-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/apache2-2.0.48-13 5.i586.rpm -
SuSE apache2-prefork-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/apache2-prefork-2 .0.48-135.i586.rpm -
SuSE apache2-worker-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/apache2-worker-2. 0.48-135.i586.rpm -
SuSE libapr0-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/libapr0-2.0.48-13 5.i586.rpm
Apache Apache 2.0.45
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.46
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.47
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz -
Apple SecUpd2004-12-02Jag.dmg
For Mac OS X v10.2.8:
http://www.apple.com/support/downloads/SecUpd2004-12-02Jag.dmg -
Apple SecUpd2004-12-02Pan.dmg
For Mac OS X v10.3.6:
http://www.apple.com/support/downloads/SecUpd2004-12-02Pan.dmg -
Apple SecUpdSrvr2004-12-02Jag.dmg
For Mac OS X Server v10.2.8:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Jag.dmg -
Apple SecUpdSrvr2004-12-02Pan.dmg
For Mac OS X Server v10.3.6:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Pan.dmg -
Mandrake apache2-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64apr0-2.0.47-6.9.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-6.9.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php
Apache Apache 2.0.48
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz -
Mandrake apache2-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64apr0-2.0.48-6.6.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.48-6.6.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
SuSE apache2-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/apache2-2.0.48-13 5.i586.patch.rpm -
SuSE apache2-2.0.48-135.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/apache2-2.0.4 8-135.x86_64.patch.rpm -
SuSE apache2-prefork-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/apache2-prefork-2 .0.48-135.i586.patch.rpm -
SuSE apache2-prefork-2.0.48-135.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/apache2-prefo rk-2.0.48-135.x86_64.patch.rpm -
SuSE apache2-worker-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/apache2-worker-2. 0.48-135.i586.patch.rpm -
SuSE apache2-worker-2.0.48-135.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/apache2-worke r-2.0.48-135.x86_64.patch.rpm -
SuSE libapr0-2.0.48-135.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/libapr0-2.0.48-13 5.i586.patch.rpm -
SuSE libapr0-2.0.48-135.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/libapr0-2.0.4 8-135.x86_64.patch.rpm -
SuSE apache2-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/apache2-2.0.48-13 5.i586.rpm -
SuSE apache2-2.0.48-135.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/apache2-2.0.4 8-135.x86_64.rpm -
SuSE apache2-prefork-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/apache2-prefork-2 .0.48-135.i586.rpm -
SuSE apache2-prefork-2.0.48-135.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/apache2-prefo rk-2.0.48-135.x86_64.rpm -
SuSE apache2-worker-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/apache2-worker-2. 0.48-135.i586.rpm -
SuSE apache2-worker-2.0.48-135.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/apache2-worke r-2.0.48-135.x86_64.rpm -
SuSE libapr0-2.0.48-135.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/libapr0-2.0.48-13 5.i586.rpm -
SuSE libapr0-2.0.48-135.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/libapr0-2.0.4 8-135.x86_64.rpm -
TurboLinux httpd-2.0.48-15.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/httpd-2.0.48-15.i586.rpm
Apache Apache 2.0.49
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz -
Conectiva apache-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-2.0.49-61251U10_1cl .i386.rpm -
Conectiva apache-devel-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-devel-2.0.49-61251U 10_1cl.i386.rpm -
Conectiva apache-doc-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-doc-2.0.49-61251U10 _1cl.i386.rpm -
Conectiva apache-htpasswd-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-htpasswd-2.0.49-612 51U10_1cl.i386.rpm -
Conectiva libapr-devel-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libapr-devel-2.0.49-61251U 10_1cl.i386.rpm -
Conectiva libapr-devel-static-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libapr-devel-static-2.0.49 -61251U10_1cl.i386.rpm -
Conectiva libapr0-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libapr0-2.0.49-61251U10_1c l.i386.rpm -
Conectiva mod_auth_ldap-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mod_auth_ldap-2.0.49-61251 U10_1cl.i386.rpm -
Conectiva mod_dav-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mod_dav-2.0.49-61251U10_1c l.i386.rpm -
Fedora httpd-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-debuginfo-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-debuginfo-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-devel-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-devel-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-manual-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-manual-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora mod_ssl-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora mod_ssl-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
SuSE apache2-2.0.49-27.11.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/apache2-2.0.49-27 .11.i586.patch.rpm -
SuSE apache2-2.0.49-27.11.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/apache2-2.0.4 9-27.11.x86_64.patch.rpm -
SuSE apache2-prefork-2.0.49-27.11.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/apache2-prefork-2 .0.49-27.11.i586.patch.rpm -
SuSE apache2-prefork-2.0.49-27.11.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/apache2-prefo rk-2.0.49-27.11.x86_64.patch.rpm -
SuSE apache2-worker-2.0.49-27.11.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/apache2-worker-2. 0.49-27.11.i586.patch.rpm -
SuSE apache2-worker-2.0.49-27.11.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/apache2-worke r-2.0.49-27.11.x86_64.patch.rpm -
SuSE libapr0-2.0.49-27.11.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/libapr0-2.0.49-27 .11.i586.patch.rpm -
SuSE libapr0-2.0.49-27.11.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/libapr0-2.0.4 9-27.11.x86_64.patch.rpm -
SuSE apache2-2.0.49-27.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/apache2-2.0.49-27 .11.i586.rpm -
SuSE apache2-2.0.49-27.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/apache2-2.0.4 9-27.11.x86_64.rpm -
SuSE apache2-prefork-2.0.49-27.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/apache2-prefork-2 .0.49-27.11.i586.rpm -
SuSE apache2-prefork-2.0.49-27.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/apache2-prefo rk-2.0.49-27.11.x86_64.rpm -
SuSE apache2-worker-2.0.49-27.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/apache2-worker-2. 0.49-27.11.i586.rpm -
SuSE apache2-worker-2.0.49-27.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/apache2-worke r-2.0.49-27.11.x86_64.rpm -
SuSE libapr0-2.0.49-27.11.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/libapr0-2.0.49-27 .11.i586.rpm -
SuSE libapr0-2.0.49-27.11.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/libapr0-2.0.4 9-27.11.x86_64.rpm -
Trustix apache-2.0.51-0.1tr.i586.rpm
Trustix Secure Linux 2.0, 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-devel-2.0.51-0.1tr.i586.rpm
Trustix Secure Linux 2.0, 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-manual-2.0.51-0.1tr.i586.rpm
Trustix Secure Linux 2.0, 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/
Apache Apache 2.0.50
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
References
Apache mod_ssl Denial Of Service Vulnerability
References:
References:
- Apache 2.0.x Latest Release Information Page (Apache Software Foundation)
- Apache Homepage (Apache Software Foundation)
- Bugzilla Bug 29964 - non-terminating i/o (Apache Software Foundation)
- RHSA-2004:349-10 - Updated httpd packages fix mod_ssl security flaw (RedHat)
- [ANNOUNCE] Apache HTTP Server 2.0.51 Released (Apache Software Foundation)