Contact | Site en Français               

 


 

VUPEN VNS v4.0

 
  Features and Options
  Free 14-Day Trial

  Partner Program

  Receive More Information
 
   
 

Latest Intelligence

 
  VUPEN Security Advisories

  Virus and Malware Alerts

  VUPEN Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Fedora Security Update Fixes Apache Cross Site Scripting and DoS Issues

Title : Fedora Security Update Fixes Apache Cross Site Scripting and DoS Issues
VUPEN ID : VUPEN/ADV-2006-0292
CVE ID : CVE-2005-2970 - CVE-2005-3352 - CVE-2005-3357
CWE ID : VUPEN VNS Only
CVSS V2 : VUPEN VNS Only
Rated as : Moderate Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-01-23


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format 

Fedora has released updated packages to address multiple vulnerabilities identified in Apache. These flaws could be exploited by remote attackers to execute arbitrary scripting code or cause a denial of service. For additional information, see : VUPEN/ADV-2005-2870 - VUPEN/ADV-2006-0056 - VUPEN/ADV-2005-2779

Affected Products

Fedora Core 4

Solution

Upgrade the affected packages :
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/
dad048a945087d7bfc78bc4ae94111ce48ecf7fb SRPMS/httpd-2.0.54-10.3.src.rpm
5b6d6597cfe9f1bb36a21227943cde8664eafdcb ppc/httpd-2.0.54-10.3.ppc.rpm
0d57fd912a03a9079c11cd8bfb49fd4f5dab7a99 ppc/httpd-devel-2.0.54-10.3.ppc.rpm
2656e7eedf0695ae66b946c3dfce4291082edac8 ppc/httpd-manual-2.0.54-10.3.ppc.rpm
8b52dfd03a206f48ded470a9b72806de3077c270 ppc/mod_ssl-2.0.54-10.3.ppc.rpm
16ec57db5e7c2565868c7adeff003881c938bf23 ppc/debug/httpd-debuginfo-2.0.54-10.3.ppc.rpm
8bed48fddd4cfd2bcbb0ee14e738c5cefa616eae x86_64/httpd-2.0.54-10.3.x86_64.rpm
6175611861e72f6798966e25663483a3dba92671 x86_64/httpd-devel-2.0.54-10.3.x86_64.rpm
94f951cbdfac7529f1f0707786ef59525797ea44 x86_64/httpd-manual-2.0.54-10.3.x86_64.rpm
1c71c5f55766d2d1152f3e287aacf70e017fe2ad x86_64/mod_ssl-2.0.54-10.3.x86_64.rpm
8a870ce0e7f5c14478f5448714babfd53ff773a1 x86_64/debug/httpd-debuginfo-2.0.54-10.3.x86_64.rpm
6db7bcdecfe33ad04ccd1f62cb865d5d85526bd5 i386/httpd-2.0.54-10.3.i386.rpm
757af8de4747675acba18a57ad50425324b62015 i386/httpd-devel-2.0.54-10.3.i386.rpm
add58762ba00bf5e967183039fd387b3c22fa857 i386/httpd-manual-2.0.54-10.3.i386.rpm
899f3e257cb5ecfe61bf9d3b65ea68faaf161293 i386/mod_ssl-2.0.54-10.3.i386.rpm
893889af90727804fd647d8f7c88bb0656c71c9d i386/debug/httpd-debuginfo-2.0.54-10.3.i386.rpm

References

http://www.vupen.com/english/advisories/2006/0292
http://www.frsirt.com/english/reference/4897

ChangeLog

2006-01-23 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time alerts with CVE, CWE, and CVSS when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

VUPEN Vulnerability
Notification Service

 

Latest Advisories

  

   
    





Copyright VUPEN © 2004-2010 - Privacy Policy