Description: | Description:
The remote host is missing an update to apache2 announced via advisory MDKSA-2005:161.
A flaw was discovered in mod_ssl's handling of the SSLVerifyClient directive. This flaw occurs if a virtual host is configured using SSLVerifyClient optional and a directive SSLVerifyClient required is set for a specific location. For servers configured in this fashion, an attacker may be able to access resources that should otherwise be protected, by not supplying a client certificate when connecting. (CVE-2005-2700)
A flaw was discovered in Apache httpd where the byterange filter would buffer certain responses into memory. If a server has a dynamic resource such as a CGI script or PHP script that generates a large amount of data, an attacker could send carefully crafted requests in order to consume resources, potentially leading to a Denial of Service. (CVE-2005-2728)
The updated packages have been patched to address these issues.
Affected versions: 10.0, 10.1, 10.2, Corporate 3.0, Multi Network Firewall 2.0
Solution: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
http://www.securityspace.com/smysecure/catid.html?in=MDKSA-2005:161 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2700 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728
Risk factor : Critical
CVSS Score: 10.0
|