Security Advisory httpd security update

Advisory: RHSA-2004:562-11
Type: Security Advisory
Severity: Important
Issued on: 2004-11-12
Last updated on: 2004-11-12
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-0885
CVE-2004-0942
CVE-2004-1834

Details

Updated httpd packages that include fixes for two security issues, as well as
other bugs, are now available.

The Apache HTTP server is a powerful, full-featured, efficient, and
freely-available Web server.

An issue has been discovered in the mod_ssl module when configured to use
the "SSLCipherSuite" directive in directory or location context. If a
particular location context has been configured to require a specific set
of cipher suites, then a client will be able to access that location using
any cipher suite allowed by the virtual host configuration. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0885 to this issue.

An issue has been discovered in the handling of white space in request
header lines using MIME folding. A malicious client could send a carefully
crafted request, forcing the server to consume large amounts of memory,
leading to a denial of service. The Common Vulnerabilities and Exposures
project (cve.mitre.org) has assigned the name CAN-2004-0942 to this issue.

Several minor bugs were also discovered, including:

- In the mod_cgi module, problems that arise when CGI scripts are
invoked from SSI pages by mod_include using the "#include virtual"
syntax have been fixed.

- In the mod_dav_fs module, problems with the handling of indirect locks
on the S/390x platform have been fixed.

Users of the Apache HTTP server who are affected by these issues should
upgrade to these updated packages, which contain backported patches.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
httpd-2.0.46-44.ent.src.rpm
File outdated by:  RHSA-2009:1579
    118f06e0317eb7d5735990049199b354
 
IA-32:
httpd-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    07294bc2ae372ae2c033f6c97a425371
httpd-devel-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    f97f7661878d345e35e49ee5b903ee97
mod_ssl-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    7ff1d8de6d421d62b5f7c35df785304e
 
x86_64:
httpd-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    1b8bce6493ff433f4fe8361b897d841e
httpd-devel-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    7ce1eb8feef44ffdb30563484f214a61
mod_ssl-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    fc576fed7de6149c17d5158e87ec600c
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
httpd-2.0.46-44.ent.src.rpm
File outdated by:  RHSA-2009:1579
    118f06e0317eb7d5735990049199b354
 
IA-32:
httpd-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    07294bc2ae372ae2c033f6c97a425371
httpd-devel-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    f97f7661878d345e35e49ee5b903ee97
mod_ssl-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    7ff1d8de6d421d62b5f7c35df785304e
 
IA-64:
httpd-2.0.46-44.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    731331f101efda7820988a76265d5b29
httpd-devel-2.0.46-44.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    95451f6b0aaffbccffb8e77c88d36cc1
mod_ssl-2.0.46-44.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    badd71a4a010b5b96d854de8b4ab14c5
 
PPC:
httpd-2.0.46-44.ent.ppc.rpm
File outdated by:  RHSA-2009:1579
    d399d5cbffd283d3e155a2e301542e6f
httpd-devel-2.0.46-44.ent.ppc.rpm
File outdated by:  RHSA-2009:1579
    ded92081a835c8e53ccbf6e8f47f244d
mod_ssl-2.0.46-44.ent.ppc.rpm
File outdated by:  RHSA-2009:1579
    4a2a5d60a34a09550910738fde57f518
 
s390:
httpd-2.0.46-44.ent.s390.rpm
File outdated by:  RHSA-2009:1579
    806ff06977f721712068a621c3981f7c
httpd-devel-2.0.46-44.ent.s390.rpm
File outdated by:  RHSA-2009:1579
    5912d5b3eb7d18071825ef4bfe3b139b
mod_ssl-2.0.46-44.ent.s390.rpm
File outdated by:  RHSA-2009:1579
    6d2866cab66c09694ba6c98b39d3e52b
 
s390x:
httpd-2.0.46-44.ent.s390x.rpm
File outdated by:  RHSA-2009:1579
    17bd982545f3e25953a4d3aff7d9ea22
httpd-devel-2.0.46-44.ent.s390x.rpm
File outdated by:  RHSA-2009:1579
    2299bd3c8d7a0a5ab525840fc453f1e1
mod_ssl-2.0.46-44.ent.s390x.rpm
File outdated by:  RHSA-2009:1579
    51cc33598d9d4559f0daf860396e5ae5
 
x86_64:
httpd-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    1b8bce6493ff433f4fe8361b897d841e
httpd-devel-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    7ce1eb8feef44ffdb30563484f214a61
mod_ssl-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    fc576fed7de6149c17d5158e87ec600c
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
httpd-2.0.46-44.ent.src.rpm
File outdated by:  RHSA-2009:1579
    118f06e0317eb7d5735990049199b354
 
IA-32:
httpd-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    07294bc2ae372ae2c033f6c97a425371
httpd-devel-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    f97f7661878d345e35e49ee5b903ee97
mod_ssl-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    7ff1d8de6d421d62b5f7c35df785304e
 
IA-64:
httpd-2.0.46-44.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    731331f101efda7820988a76265d5b29
httpd-devel-2.0.46-44.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    95451f6b0aaffbccffb8e77c88d36cc1
mod_ssl-2.0.46-44.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    badd71a4a010b5b96d854de8b4ab14c5
 
x86_64:
httpd-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    1b8bce6493ff433f4fe8361b897d841e
httpd-devel-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    7ce1eb8feef44ffdb30563484f214a61
mod_ssl-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    fc576fed7de6149c17d5158e87ec600c
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
httpd-2.0.46-44.ent.src.rpm
File outdated by:  RHSA-2009:1579
    118f06e0317eb7d5735990049199b354
 
IA-32:
httpd-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    07294bc2ae372ae2c033f6c97a425371
httpd-devel-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    f97f7661878d345e35e49ee5b903ee97
mod_ssl-2.0.46-44.ent.i386.rpm
File outdated by:  RHSA-2009:1579
    7ff1d8de6d421d62b5f7c35df785304e
 
IA-64:
httpd-2.0.46-44.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    731331f101efda7820988a76265d5b29
httpd-devel-2.0.46-44.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    95451f6b0aaffbccffb8e77c88d36cc1
mod_ssl-2.0.46-44.ent.ia64.rpm
File outdated by:  RHSA-2009:1579
    badd71a4a010b5b96d854de8b4ab14c5
 
x86_64:
httpd-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    1b8bce6493ff433f4fe8361b897d841e
httpd-devel-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    7ce1eb8feef44ffdb30563484f214a61
mod_ssl-2.0.46-44.ent.x86_64.rpm
File outdated by:  RHSA-2009:1579
    fc576fed7de6149c17d5158e87ec600c
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

132593 - mod_dav_fs: indirect lock refresh broken on s390x
134825 - CAN-2004-0885 SSLCipherSuite bypass
138064 - CAN-2004-0942 Memory consumption DoS


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/