Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2004:245

The remote host is missing updates announced in
advisory RHSA-2004:245.

The Apache HTTP Server is a powerful, full-featured, efficient, and
freely-available Web server.

A buffer overflow was found in the Apache proxy module, mod_proxy, which
can be triggered by receiving an invalid Content-Length header. In order
to exploit this issue, an attacker would need an Apache installation
that was configured as a proxy to connect to a malicious site. This would
cause the Apache child processing the request to crash. The Common
Vulnerabilities and Exposures project ( has assigned the name
CVE-2004-0492 to this issue.

On Red Hat Enterprise Linux platforms Red Hat believes this issue cannot
lead to remote code execution. This issue also does not represent a Denial
of Service attack as requests will continue to be handled by other Apache
child processes.

A stack buffer overflow was discovered in mod_ssl which can be triggered if
using the FakeBasicAuth option. If mod_ssl is sent a client certificate
with a subject DN field longer than 6000 characters, a stack overflow can
occur if FakeBasicAuth has been enabled. In order to exploit this issue
the carefully crafted malicious certificate would have to be signed by a
Certificate Authority which mod_ssl is configured to trust. The Common
Vulnerabilities and Exposures project ( has assigned the name
CVE-2004-0488 to this issue.

This update also fixes a DNS handling bug in mod_proxy.

The mod_auth_digest module is now included in the Apache package and should
be used instead of mod_digest for sites requiring Digest authentication.

Red Hat Enterprise Linux 2.1 users of the Apache HTTP Server should upgrade
to these erratum packages, which contains Apache version 1.3.27 with
backported patches correcting these issues.

Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

Risk factor : Critical

CVSS Score:

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0488
BugTraq ID: 10355
Bugtraq: 20040527 [OpenPKG-SA-2004.026] OpenPKG Security Advisory (apache) (Google Search)
Bugtraq: 20040601 TSSA-2004-008 - apache (Google Search)
Debian Security Information: DSA-532 (Google Search)
HPdes Security Advisory: SSRT4777
HPdes Security Advisory: SSRT4788
RedHat Security Advisories: RHSA-2004:245
SGI Security Advisory: 20040605-01-U
XForce ISS Database: apache-modssl-uuencode-bo(16214)
Common Vulnerability Exposure (CVE) ID: CVE-2004-0492
Bugtraq: 20040611 [OpenPKG-SA-2004.029] OpenPKG Security Advisory (apache) (Google Search)
CERT/CC vulnerability note: VU#541310
Debian Security Information: DSA-525 (Google Search)
HPdes Security Advisory: HPSBOV02683
HPdes Security Advisory: SSRT090208
XForce ISS Database: apache-modproxy-contentlength-bo(16387)
CopyrightCopyright (c) 2005 E-Soft Inc.

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2021 E-Soft Inc. All rights reserved.