The Apache HTTP Server is a popular web server.
It was discovered that mod_proxy_ajp incorrectly returned an âInternal
Server Errorâ response when processing certain malformed requests, which
caused the back-end server to be marked as failed in configurations where
mod_proxy is used in load balancer mode. A remote attacker could cause
mod_proxy to not send requests to back-end AJP (Apache JServ Protocol)
servers for the retry timeout period (60 seconds by default) by sending
specially-crafted requests. (CVE-2010-0408)
A use-after-free flaw was discovered in the way the Apache HTTP Server
handled request headers in subrequests. In configurations where subrequests
are used, a multithreaded MPM (Multi-Processing Module) could possibly leak
information from other requests in request replies. (CVE-2010-0434)
This update also adds the following enhancement:
Refer to the following Red Hat Knowledgebase article for more details about
the changed mod_ssl behavior: http://kbase.redhat.com/faq/docs/DOC-20491
All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues and add this enhancement. After
installing the updated packages, the httpd daemon must be restarted for the
update to take effect.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | 5 | x86_64 | mod_ssl | <Â 2.2.3-31.el5_4.4 | mod_ssl-2.2.3-31.el5_4.4.x86_64.rpm |
RedHat | 5 | i386 | mod_ssl | <Â 2.2.3-31.el5_4.4 | mod_ssl-2.2.3-31.el5_4.4.i386.rpm |
RedHat | 5 | ia64 | httpd-manual | <Â 2.2.3-31.el5_4.4 | httpd-manual-2.2.3-31.el5_4.4.ia64.rpm |
RedHat | 5 | ppc | httpd-devel | <Â 2.2.3-31.el5_4.4 | httpd-devel-2.2.3-31.el5_4.4.ppc.rpm |
RedHat | 5 | x86_64 | httpd-devel | <Â 2.2.3-31.el5_4.4 | httpd-devel-2.2.3-31.el5_4.4.x86_64.rpm |
RedHat | 5 | s390 | httpd-devel | <Â 2.2.3-31.el5_4.4 | httpd-devel-2.2.3-31.el5_4.4.s390.rpm |
RedHat | 5 | s390x | httpd | <Â 2.2.3-31.el5_4.4 | httpd-2.2.3-31.el5_4.4.s390x.rpm |
RedHat | 5 | x86_64 | httpd | <Â 2.2.3-31.el5_4.4 | httpd-2.2.3-31.el5_4.4.x86_64.rpm |
RedHat | 5 | src | httpd | <Â 2.2.3-31.el5_4.4 | httpd-2.2.3-31.el5_4.4.src.rpm |
RedHat | 5 | s390x | httpd-manual | <Â 2.2.3-31.el5_4.4 | httpd-manual-2.2.3-31.el5_4.4.s390x.rpm |