Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
BID:9826
Info
Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
| Bugtraq ID: | 9826 |
| Class: | Design Error |
| CVE: |
CVE-2004-0113 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | Discovery of this vulnerability has been credited to Mick Wall <[email protected]>. |
| Vulnerable: |
Turbolinux Turbolinux Desktop 10.0 SGI ProPack 3.0 Redhat mod_ssl-2.0.40-21.i386.rpm Redhat httpd-manual-2.0.40-21.i386.rpm Redhat httpd-devel-2.0.40-21.i386.rpm Redhat httpd-2.0.40-21.i386.rpm HP HP-UX 11.23 HP HP-UX 11.22 HP HP-UX 11.11 HP HP-UX 11.0 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X 10.3.3 Apple Mac OS X 10.2.8 Apache Apache 2.0.48 Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 |
| Not Vulnerable: |
Apache Apache 2.0.49 |
Discussion
Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
mod_ssl has been reported to be prone to a remote denial of service vulnerability. It has been reported that the issue is as a result of a memory leak and will present itself when standard HTTP requests are handled on the SSL port of an affected Apache server.
mod_ssl has been reported to be prone to a remote denial of service vulnerability. It has been reported that the issue is as a result of a memory leak and will present itself when standard HTTP requests are handled on the SSL port of an affected Apache server.
Exploit / POC
Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
Solution:
The vendor has addressed this issue, the fix is available through CVS at the following location:
http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_io.c?r1=1.117&r2=1.118
This issue is also addressed in Apache 2.0.49.
Red Hat has released an advisory (RHSA-2004:182-01) and fixes to address this issue in Red Hat Linux 9. Red Hat Linux users are advised to see the referenced advisory for further details regarding obtaining and applying appropriate fixes.
Turbolinux have released a security advisory (TLSA-2004-11), and updates to address this issue in Turbolinux products. Users are advised to apply these updates as soon as possible, further details regarding obtaining and installing these updates can be found in the referenced advisory.
Gentoo has released advisory GLSA200403-04 to address this issue. Gentoo updates may be applied with the following commands:
emerge sync
emerge -pv ">=net-www/apache-2.0.49"
emerge ">=net-www/apache-2.0.49"
Additional details are included in the Gentoo advisory for users who are migrating from 2.0.48-r1 or earlier releases.
Netwosix Linux has released an advisory dealing with this issue. Please see the reference section for more details.
Trustix has released an advisory that includes updates for this issue.
Conectiva Linux has released an advisory CLSA-2004:839 with fixes to address this issue. Please see the referenced advisory for more information.
SUSE has released an advisory SuSE-SA:2004:009 to address this and other issues. Please see the advisory for more information.
HP has released security bulletin HPSBUX01022 dealing with this issue as well as fixes for their HP-UX architecture. Please see the referenced advisory for more information and details on obtaining fixes.
Apple has released security advisory APPLE-SA-2004-05-03 dealing with this and other issues. Please see the referenced advisory for more information.
Mandrakelinux has released an advisory MDKSA-2004:043 to address this issue. Please see the referenced advisory for more information.
RedHat has released an advisory FEDORA-2004-117 to address this issue in Fedora Core 1. Please see the referenced advisory for more information.
HP has released advisory HPSBTU01049 - SSRT4717 dealing with this and other issues. Please see the referenced advisory for more information.
SGI has released an advisory (20040506-01-U) with Patch 10075 for SGI ProPack 3 to address this and other issues. Please see the referenced advisory for more information.
Redhat httpd-manual-2.0.40-21.i386.rpm
Redhat httpd-2.0.40-21.i386.rpm
Redhat httpd-devel-2.0.40-21.i386.rpm
Redhat mod_ssl-2.0.40-21.i386.rpm
Turbolinux Turbolinux Desktop 10.0
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X Server 10.3.3
Apple Mac OS X 10.3.3
Apache Apache 2.0.35
Apache Apache 2.0.36
Apache Apache 2.0.37
Apache Apache 2.0.38
Apache Apache 2.0.39
Apache Apache 2.0.40
Apache Apache 2.0.41
Apache Apache 2.0.42
Apache Apache 2.0.43
Apache Apache 2.0.44
Apache Apache 2.0.45
Apache Apache 2.0.46
Apache Apache 2.0.47
Apache Apache 2.0.48
SGI ProPack 3.0
Solution:
The vendor has addressed this issue, the fix is available through CVS at the following location:
http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_io.c?r1=1.117&r2=1.118
This issue is also addressed in Apache 2.0.49.
Red Hat has released an advisory (RHSA-2004:182-01) and fixes to address this issue in Red Hat Linux 9. Red Hat Linux users are advised to see the referenced advisory for further details regarding obtaining and applying appropriate fixes.
Turbolinux have released a security advisory (TLSA-2004-11), and updates to address this issue in Turbolinux products. Users are advised to apply these updates as soon as possible, further details regarding obtaining and installing these updates can be found in the referenced advisory.
Gentoo has released advisory GLSA200403-04 to address this issue. Gentoo updates may be applied with the following commands:
emerge sync
emerge -pv ">=net-www/apache-2.0.49"
emerge ">=net-www/apache-2.0.49"
Additional details are included in the Gentoo advisory for users who are migrating from 2.0.48-r1 or earlier releases.
Netwosix Linux has released an advisory dealing with this issue. Please see the reference section for more details.
Trustix has released an advisory that includes updates for this issue.
Conectiva Linux has released an advisory CLSA-2004:839 with fixes to address this issue. Please see the referenced advisory for more information.
SUSE has released an advisory SuSE-SA:2004:009 to address this and other issues. Please see the advisory for more information.
HP has released security bulletin HPSBUX01022 dealing with this issue as well as fixes for their HP-UX architecture. Please see the referenced advisory for more information and details on obtaining fixes.
Apple has released security advisory APPLE-SA-2004-05-03 dealing with this and other issues. Please see the referenced advisory for more information.
Mandrakelinux has released an advisory MDKSA-2004:043 to address this issue. Please see the referenced advisory for more information.
RedHat has released an advisory FEDORA-2004-117 to address this issue in Fedora Core 1. Please see the referenced advisory for more information.
HP has released advisory HPSBTU01049 - SSRT4717 dealing with this and other issues. Please see the referenced advisory for more information.
SGI has released an advisory (20040506-01-U) with Patch 10075 for SGI ProPack 3 to address this and other issues. Please see the referenced advisory for more information.
Redhat httpd-manual-2.0.40-21.i386.rpm
-
RedHat httpd-manual-2.0.40-21.11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-manual-2.0.40-21.11.i386.r pm
Redhat httpd-2.0.40-21.i386.rpm
-
RedHat httpd-2.0.40-21.11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-2.0.40-21.11.i386.rpm
Redhat httpd-devel-2.0.40-21.i386.rpm
-
RedHat httpd-devel-2.0.40-21.11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-devel-2.0.40-21.11.i386.rp m
Redhat mod_ssl-2.0.40-21.i386.rpm
-
RedHat mod_ssl-2.0.40-21.11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/mod_ssl-2.0.40-21.11.i386.rpm
Turbolinux Turbolinux Desktop 10.0
-
Turbolinux httpd-2.0.47-8.i586.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/upd ates/RPMS/httpd-2.0.47-8.i586.rpm
Apple Mac OS X 10.2.8
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg
Apple Mac OS X Server 10.2.8
-
Apple Darwin SecUpdSrvr2004-02-23Jag.dmg
http://www.info.apple.com/kbnum/n120322 -
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg
Apple Mac OS X Server 10.3.3
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg
Apple Mac OS X 10.3.3
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg
Apache Apache 2.0.35
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.36
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.37
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.38
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.39
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.40
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi -
RedHat httpd-2.0.40-21.11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-2.0.40-21.11.i386.rpm -
RedHat httpd-devel-2.0.40-21.11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-devel-2.0.40-21.11.i386.rp m -
RedHat httpd-manual-2.0.40-21.11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-manual-2.0.40-21.11.i386.r pm -
RedHat mod_ssl-2.0.40-21.11.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/mod_ssl-2.0.40-21.11.i386.rpm
Apache Apache 2.0.41
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.42
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.43
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.44
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.45
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi -
Conectiva apache-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-2.0.45-28790U90_6cl. i386.rpm -
Conectiva apache-devel-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-devel-2.0.45-28790U9 0_6cl.i386.rpm -
Conectiva apache-doc-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-doc-2.0.45-28790U90_ 6cl.i386.rpm -
Conectiva apache-htpasswd-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-htpasswd-2.0.45-2879 0U90_6cl.i386.rpm -
Conectiva libapr-devel-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-2.0.45-28790U9 0_6cl.i386.rpm -
Conectiva libapr-devel-static-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-static-2.0.45- 28790U90_6cl.i386.rpm -
Conectiva libapr0-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr0-2.0.45-28790U90_6cl .i386.rpm -
Conectiva mod_auth_ldap-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_auth_ldap-2.0.45-28790U 90_6cl.i386.rpm -
Conectiva mod_dav-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_dav-2.0.45-28790U90_6cl .i386.rpm
Apache Apache 2.0.46
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Apache 2.0.47
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi -
Mandrake apache2-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64apr0-2.0.47-6.4.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-1.7.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-1.7.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-6.4.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php
Apache Apache 2.0.48
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi -
Mandrake apache2-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.48-6.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Trustix apache-2.0.49-1tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.0/rpms/apache-2.0.49-1tr.i 586.rpm -
Trustix apache-2.0.49-2tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.1/rpms/apache-2.0.49-2tr.i 586.rpm -
Trustix apache-dbm-2.0.49-2tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.1/rpms/apache-dbm-2.0.49-2 tr.i586.rpm -
Trustix apache-devel-2.0.49-1tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.0/rpms/apache-devel-2.0.49 -1tr.i586.rpm -
Trustix apache-devel-2.0.49-2tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.1/rpms/apache-devel-2.0.49 -2tr.i586.rpm -
Trustix apache-manual-2.0.49-1tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.0/rpms/apache-manual-2.0.4 9-1tr.i586.rpm -
Trustix apache-manual-2.0.49-2tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.1/rpms/apache-manual-2.0.4 9-2tr.i586.rpm
SGI ProPack 3.0
-
SGI patch10075.tar.gz
ftp://patches.sgi.com/support/free/security/patches/ProPack/3/
References
Apache Mod_SSL HTTP Request Remote Denial Of Service Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- CLSA-2004:839 - apache (Conectiva)
- Overview of security vulnerabilities in Apache httpd 2.0 (ApacheWeek)