5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
0.072 Low
EPSS
Percentile
94.0%
CentOS Errata and Security Advisory CESA-2008:0967
The Apache HTTP Server is a popular Web server.
A flaw was found in the mod_proxy Apache module. An attacker in control of
a Web server to which requests were being proxied could have caused a
limited denial of service due to CPU consumption and stack exhaustion.
(CVE-2008-2364)
A flaw was found in the mod_proxy_ftp Apache module. If Apache was
configured to support FTP-over-HTTP proxying, a remote attacker could have
performed a cross-site scripting attack. (CVE-2008-2939)
In addition, these updated packages fix a bug found in the handling of the
โProxyRemoteMatchโ directive in the Red Hat Enterprise Linux 4 httpd
packages. This bug is not present in the Red Hat Enterprise Linux 3 or Red
Hat Enterprise Linux 5 packages.
Users of httpd should upgrade to these updated packages, which contain
backported patches to correct these issues.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2008-November/077551.html
https://lists.centos.org/pipermail/centos-announce/2008-November/077552.html
https://lists.centos.org/pipermail/centos-announce/2008-November/077555.html
https://lists.centos.org/pipermail/centos-announce/2008-November/077556.html
https://lists.centos.org/pipermail/centos-announce/2008-November/077566.html
https://lists.centos.org/pipermail/centos-announce/2008-November/077567.html
https://lists.centos.org/pipermail/centos-announce/2008-November/077572.html
https://lists.centos.org/pipermail/centos-announce/2008-November/077573.html
https://lists.centos.org/pipermail/centos-announce/2008-November/077580.html
https://lists.centos.org/pipermail/centos-announce/2008-November/077582.html
https://lists.centos.org/pipermail/centos-announce/2008-November/090310.html
https://lists.centos.org/pipermail/centos-announce/2008-November/090311.html
https://lists.centos.org/pipermail/centos-announce/2008-November/090314.html
https://lists.centos.org/pipermail/centos-announce/2008-November/090315.html
Affected packages:
httpd
httpd-devel
httpd-manual
httpd-suexec
mod_ssl
Upstream details at:
https://access.redhat.com/errata/RHSA-2008:0967
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 5 | i386 | httpd | <ย 2.2.3-11.el5.centos.4 | httpd-2.2.3-11.el5.centos.4.i386.rpm |
CentOS | 5 | i386 | httpd-devel | <ย 2.2.3-11.el5.centos.4 | httpd-devel-2.2.3-11.el5.centos.4.i386.rpm |
CentOS | 5 | i386 | httpd-manual | <ย 2.2.3-11.el5.centos.4 | httpd-manual-2.2.3-11.el5.centos.4.i386.rpm |
CentOS | 5 | i386 | mod_ssl | <ย 2.2.3-11.el5.centos.4 | mod_ssl-2.2.3-11.el5.centos.4.i386.rpm |
CentOS | 5 | x86_64 | httpd | <ย 2.2.3-11.el5.centos.4 | httpd-2.2.3-11.el5.centos.4.x86_64.rpm |
CentOS | 5 | i386 | httpd-devel | <ย 2.2.3-11.el5.centos.4 | httpd-devel-2.2.3-11.el5.centos.4.i386.rpm |
CentOS | 5 | x86_64 | httpd-devel | <ย 2.2.3-11.el5.centos.4 | httpd-devel-2.2.3-11.el5.centos.4.x86_64.rpm |
CentOS | 5 | x86_64 | httpd-manual | <ย 2.2.3-11.el5.centos.4 | httpd-manual-2.2.3-11.el5.centos.4.x86_64.rpm |
CentOS | 5 | x86_64 | mod_ssl | <ย 2.2.3-11.el5.centos.4 | mod_ssl-2.2.3-11.el5.centos.4.x86_64.rpm |
CentOS | 3 | i386 | httpd | <ย 2.0.46-71.ent | httpd-2.0.46-71.ent.i386.rpm |