Description: | Description:
The remote host is missing an update to httpd announced via advisory FEDORA-2005-638.
Apache is a powerful, full-featured, efficient, and freely-available Web server. Apache is also the most popular Web server on the Internet.
Update Information:
This update includes version 2.0.53 of the Apache HTTP server, and also adds security fixes for CVE CVE-2005-2088 and CVE CVE-2005-1268. * Tue Jul 26 2005 Joe Orton 2.0.53-3.2 - add security fix for C-L vs T-E handling (#162245, CVE CVE-2005-2088) - mod_ssl: add security fix for CRL overflow (CVE CVE-2005-1268) - mod_ssl: fix to enable output buffering (upstream #35279) - mod_ssl: fix for picking up -shutdown options (upstream #34452) - mod_include: fix variable corruption in nested includes (upstream #12655) - mod_auth_digest: fix hostinfo comparison in CONNECT requests - add piped logger fixes (w/Jeff Trawick) - mod_userdir: fix memory allocation issue (upstream #34588)
* Mon Mar 21 2005 Joe Orton 2.0.53-3.1 - update to 2.0.53 - apachectl: use runuser so apachectl testconfig produces output - apachectl: restore use of $OPTIONS again (#115910) - mod_ssl: set user from SSLUserName in access hook (upstream #31418) - htdigest: fix permissions of created files (upstream #33765) - httpd.init: refuse to restart if config syntax test fails
Solution: Apply the appropriate updates.
This update can be downloaded from: http://download.fedora.redhat.com/pub/fedora/linux/core/updates/3/
This update can also be installed with the Update Agent you can launch the Update Agent with the 'up2date' command.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2005-638
Risk factor : Medium
CVSS Score: 5.0
|