Bug Fix Advisory httpd bug fix update

Advisory: RHBA-2007:0445-2
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2007-06-11
Last updated on: 2007-06-11
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: N/A

Details

Updated httpd packages that fix several bugs are now available.

The Apache HTTP Server is a popular and freely-available Web server.

Bugs fixed in these updated packages include:

* the mod_expires module prevented Expires headers from being sent in
304 responses.

* the mod_setenvif module prevented environment variables being set for
particular configurations.

* the mod_disk_cache module could allow incorrect content-type headers
to be sent in responses served from the cache.

* the handling of regular expressions in the ProxyRemoteMatch directive
in the mod_proxy module was incorrect; the inverse of the result of
matching the regular expression was used to determine whether a remote
proxy server was used.

* a change introduced in a previous update to relax the allowed syntax
of the Host: request header has been reverted.

* the mod_ssl module prevented "close_notify" alerts from being sent
when an SSL/TLS connection was shut down. Clients are unable to detect a
clean SSL connection closure without these alerts being sent.

Users of httpd are advised to upgrade to the updated packages, which
resolve these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
httpd-2.0.46-63.ent.src.rpm
File outdated by:  RHSA-2009:1579
    ab40b84788dbeb7520077dcabd06dbdf
 
IA-32:
httpd-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    530d1eb5ec638637682ca9ee7bdd1184
httpd-devel-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    3dc914067ca806131ab738be4610ca8e
mod_ssl-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    4a2ad8673b902cb778a1ffe597189e7b
 
x86_64:
httpd-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    62c4b501baf8b04a08c9773fa0ad01ee
httpd-devel-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    046d98be8f3adcc693c790f0163361c8
mod_ssl-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    523917d015c562a7ea90c69fb60c406e
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
httpd-2.0.46-63.ent.src.rpm
File outdated by:  RHSA-2009:1579
    ab40b84788dbeb7520077dcabd06dbdf
 
IA-32:
httpd-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    530d1eb5ec638637682ca9ee7bdd1184
httpd-devel-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    3dc914067ca806131ab738be4610ca8e
mod_ssl-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    4a2ad8673b902cb778a1ffe597189e7b
 
IA-64:
httpd-2.0.46-63.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    5adace8ffd64e6c8afa9ad466e2446c3
httpd-devel-2.0.46-63.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    e3edbc57f336174804fa65c8d2eccfd4
mod_ssl-2.0.46-63.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    c037db4c54b9e88c259d62ade5a6cbc0
 
PPC:
httpd-2.0.46-63.ent.ppc.rpm
File outdated by:  RHSA-2009:1579
    da8f4c4dca84bc302a27c186ec36e1b2
httpd-devel-2.0.46-63.ent.ppc.rpm
File outdated by:  RHSA-2009:1579
    9e6de409d7958229cdc2aa01724e6586
mod_ssl-2.0.46-63.ent.ppc.rpm
File outdated by:  RHSA-2009:1579
    1127aab3cd9d6e5f6bfe0e5b0a3d5352
 
s390:
httpd-2.0.46-63.ent.s390.rpm
File outdated by:  RHSA-2009:1579
    712a5c1d0e3957812164984022ddfb4b
httpd-devel-2.0.46-63.ent.s390.rpm
File outdated by:  RHSA-2009:1579
    d07afbed5c7c98ccc3e635170324e333
mod_ssl-2.0.46-63.ent.s390.rpm
File outdated by:  RHSA-2009:1579
    2840fc6ed930467d5f0bce1c2604ce2a
 
s390x:
httpd-2.0.46-63.ent.s390x.rpm
File outdated by:  RHSA-2009:1579
    cfc2b3f73d3ccf17ed563dc0dee16c7f
httpd-devel-2.0.46-63.ent.s390x.rpm
File outdated by:  RHSA-2009:1579
    7b6463cbb1e8acf8b71c7d9900854427
mod_ssl-2.0.46-63.ent.s390x.rpm
File outdated by:  RHSA-2009:1579
    2904f08103e7aa85026c166b6688c14e
 
x86_64:
httpd-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    62c4b501baf8b04a08c9773fa0ad01ee
httpd-devel-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    046d98be8f3adcc693c790f0163361c8
mod_ssl-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    523917d015c562a7ea90c69fb60c406e
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
httpd-2.0.46-63.ent.src.rpm
File outdated by:  RHSA-2009:1579
    ab40b84788dbeb7520077dcabd06dbdf
 
IA-32:
httpd-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    530d1eb5ec638637682ca9ee7bdd1184
httpd-devel-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    3dc914067ca806131ab738be4610ca8e
mod_ssl-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    4a2ad8673b902cb778a1ffe597189e7b
 
IA-64:
httpd-2.0.46-63.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    5adace8ffd64e6c8afa9ad466e2446c3
httpd-devel-2.0.46-63.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    e3edbc57f336174804fa65c8d2eccfd4
mod_ssl-2.0.46-63.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    c037db4c54b9e88c259d62ade5a6cbc0
 
x86_64:
httpd-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    62c4b501baf8b04a08c9773fa0ad01ee
httpd-devel-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    046d98be8f3adcc693c790f0163361c8
mod_ssl-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    523917d015c562a7ea90c69fb60c406e
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
httpd-2.0.46-63.ent.src.rpm
File outdated by:  RHSA-2009:1579
    ab40b84788dbeb7520077dcabd06dbdf
 
IA-32:
httpd-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    530d1eb5ec638637682ca9ee7bdd1184
httpd-devel-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    3dc914067ca806131ab738be4610ca8e
mod_ssl-2.0.46-63.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    4a2ad8673b902cb778a1ffe597189e7b
 
IA-64:
httpd-2.0.46-63.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    5adace8ffd64e6c8afa9ad466e2446c3
httpd-devel-2.0.46-63.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    e3edbc57f336174804fa65c8d2eccfd4
mod_ssl-2.0.46-63.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    c037db4c54b9e88c259d62ade5a6cbc0
 
x86_64:
httpd-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    62c4b501baf8b04a08c9773fa0ad01ee
httpd-devel-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    046d98be8f3adcc693c790f0163361c8
mod_ssl-2.0.46-63.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    523917d015c562a7ea90c69fb60c406e
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

168850 - mod_expires doesn't correctly add Expires headers for HTTP 304 pages
177322 - mod_deflate doesn't compress documents to MSIE
183880 - Content-type wrong of .css and .html files after enabling mod_cache/mod_disk_cache
218317 - mod_proxy: ProxyRemoteMatch uses remote proxy if regex does *not* match



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/