Descripción: | Summary: The remote host is missing an update for the 'Apache' package(s) announced via the SSA:2006-129-01 advisory.
Vulnerability Insight: New Apache packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current to fix security issues.
More details about the issues may be found in the Common Vulnerabilities and Exposures (CVE) database:
[link moved to references]
In addition, new mod_ssl packages for Apache 1.3.35 are available for all of these versions of Slackware, and new versions of PHP are available for Slackware -current. These additional packages do not fix security issues, but may be required on your system depending on your Apache setup.
One more note about this round of updates: the packages have been given build versions that indicate which version of Slackware they are meant to patch, such as -1_slack8.1, or -1_slack9.0, etc. This should help to avoid some of the issues with automatic upgrade tools by providing a unique package name when the same fix is deployed across multiple Slackware versions. Only patches applied to -current will have the simple build number, such as -1.
Here are the details from the Slackware 10.2 ChangeLog: +--------------------------+ patches/packages/apache-1.3.35-i486-1_slack10.2.tgz: Upgraded to apache-1.3.35. From the official announcement: Of particular note is that 1.3.35 addresses and fixes 1 potential security issue: CVE-2005-3352 (cve.mitre.org) mod_imap: Escape untrusted referer header before outputting in HTML to avoid potential cross-site scripting. Change also made to ap_escape_html so we escape quotes. Reported by JPCERT For more information, see: [link moved to references] (* Security fix *) patches/packages/mod_ssl-2.8.26_1.3.35-i486-1_slack10.2.tgz: Upgraded to mod_ssl-2.8.26-1.3.35. This is an updated version designed for Apache 1.3.35. +--------------------------+
Affected Software/OS: 'Apache' package(s) on Slackware 8.1, Slackware 9.0, Slackware 9.1, Slackware 10.0, Slackware 10.1, Slackware 10.2, Slackware current.
Solution: Please install the updated package(s).
CVSS Score: 4.3
CVSS Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
|