Description: | Description:
The remote host is missing updates announced in advisory TSLSA-2004-0027.
From the Apache http server main page: In mod_digest, verify whether the nonce returned in the client response is one we issued ourselves. This problem does not affect mod_auth_digest.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-0987 to this issue.
Escape arbitrary data before writing into the errorlog.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-0020 to this issue.
Fix starvation issue on listening sockets where a short-lived connection on a rarely-accessed listening socket will cause a child to hold the accept mutex and block out new connections until another connection arrives on that rarely-accessed listening socket.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0174 to this issue.
Fix parsing of Allow/Deny rules using IP addresses without a netmask
issue is only known to affect big-endian 64-bit platforms
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2003-0993 to this issue.
Solution: Update your system with the packages as indicated in the referenced security advisory.
http://www.securityspace.com/smysecure/catid.html?in=TSLSA-2004-0027
Risk factor : High
CVSS Score: 7.5
|