Security Advisory Moderate: httpd security update

Advisory: RHSA-2008:0009-3
Type: Security Advisory
Severity: Moderate
Issued on: 2008-01-21
Last updated on: 2008-01-21
Affected Products: Red Hat Application Stack v2
OVAL: N/A
CVEs (cve.mitre.org): CVE-2007-5000
CVE-2007-6388
CVE-2007-6421
CVE-2007-6422
CVE-2008-0005

Details

Updated Apache httpd packages that correct several security issues are now
available for Red Hat Application Stack v2.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

The Apache HTTP Server is a popular and freely-available Web server.

These updated httpd packages resolve the following security issues:

A flaw was found in the mod_imagemap module. On sites where mod_imagemap
was enabled and an imagemap file was publicly available, a cross-site
scripting attack was possible. (CVE-2007-5000)

A flaw was found in the mod_status module. On sites where mod_status was
enabled and the status pages were publicly accessible, a cross-site
scripting attack was possible. (CVE-2007-6388)

A flaw was found in the mod_proxy_balancer module. On sites where
mod_proxy_balancer was enabled, a cross-site scripting attack against an
authorized user was possible. (CVE-2007-6421)

A flaw was found in the mod_proxy_balancer module. On sites where
mod_proxy_balancer was enabled, an authorized user could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. This could lead to a denial of service if using a
threaded Multi-Processing Module. (CVE-2007-6422)

A flaw was found in the mod_proxy_ftp module. On sites where mod_proxy_ftp
was enabled and a forward proxy was configured, a cross-site scripting
attack was possible against browsers which do not correctly derive the
response character set following the rules in RFC 2616. (CVE-2008-0005)

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct these issues. Users should restart httpd
after installing this update.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Updated packages

Red Hat Application Stack v2

SRPMS:
httpd-2.2.4-9.el5s2.src.rpm
File outdated by:  RHSA-2008:0505
    d216b6c14832d00c491ff4e75e74c47a
 
IA-32:
httpd-2.2.4-9.el5s2.i386.rpm
File outdated by:  RHSA-2008:0505
    a6b7f9a424ff97434e5e8d29de6d60db
httpd-devel-2.2.4-9.el5s2.i386.rpm
File outdated by:  RHSA-2008:0505
    1f300dc3ff23ee5edfd219aaef740e2e
httpd-manual-2.2.4-9.el5s2.i386.rpm
File outdated by:  RHSA-2008:0505
    b09ca10a1dc577659136ced930952876
mod_ssl-2.2.4-9.el5s2.i386.rpm
File outdated by:  RHSA-2008:0505
    a7b61988a8c087877eb3b36f0918c734
 
x86_64:
httpd-2.2.4-9.el5s2.x86_64.rpm
File outdated by:  RHSA-2008:0505
    c9af7934e2d827ee70264bd9d7dd2579
httpd-devel-2.2.4-9.el5s2.i386.rpm     1f300dc3ff23ee5edfd219aaef740e2e
httpd-devel-2.2.4-9.el5s2.x86_64.rpm
File outdated by:  RHSA-2008:0505
    88c54aaa2c90caf1ab60c2247bbf92bd
httpd-manual-2.2.4-9.el5s2.x86_64.rpm
File outdated by:  RHSA-2008:0505
    711ae09361044acd6781e6bc2b34e267
mod_ssl-2.2.4-9.el5s2.x86_64.rpm
File outdated by:  RHSA-2008:0505
    db5bbeb1b07bb2d7464d771628a29de1
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

419931 - CVE-2007-5000 mod_imagemap XSS
427228 - CVE-2007-6388 apache mod_status cross-site scripting
427229 - CVE-2007-6421 httpd mod_proxy_balancer cross-site scripting
427230 - CVE-2007-6422 httpd mod_proxy_balancer crash
427739 - CVE-2008-0005 mod_proxy_ftp XSS


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/