Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:
Category:Red Hat Local Security Checks
Title:RedHat Security Advisory RHSA-2011:1391
The remote host is missing updates announced in
advisory RHSA-2011:1391.

The Apache HTTP Server is a popular web server.

It was discovered that the Apache HTTP Server did not properly validate the
request URI for proxied requests. In certain configurations, if a reverse
proxy used the ProxyPassMatch directive, or if it used the RewriteRule
directive with the proxy flag, a remote attacker could make the proxy
connect to an arbitrary server, possibly disclosing sensitive information
from internal web servers not directly accessible to the attacker.

It was discovered that mod_proxy_ajp incorrectly returned an Internal
Server Error response when processing certain malformed HTTP requests,
which caused the back-end server to be marked as failed in configurations
where mod_proxy was used in load balancer mode. A remote attacker could
cause mod_proxy to not send requests to back-end AJP (Apache JServ
Protocol) servers for the retry timeout period or until all back-end
servers were marked as failed. (CVE-2011-3348)

Red Hat would like to thank Context Information Security for reporting the
CVE-2011-3368 issue.

This update also fixes the following bug:

* The fix for CVE-2011-3192 provided by the RHSA-2011:1245 update
introduced regressions in the way httpd handled certain Range HTTP header
values. This update corrects those regressions. (BZ#736592)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.

Please note that this update is available via
Red Hat Network. To use Red Hat Network, launch the Red
Hat Update Agent with the following command: up2date

Risk factor : Medium

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-3348
BugTraq ID: 49616
HPdes Security Advisory: HPSBMU02704
HPdes Security Advisory: HPSBUX02707
HPdes Security Advisory: SSRT100619
HPdes Security Advisory: SSRT100626
RedHat Security Advisories: RHSA-2012:0542
RedHat Security Advisories: RHSA-2012:0543
XForce ISS Database: apache-modproxyajp-dos(69804)
Common Vulnerability Exposure (CVE) ID: CVE-2011-3368
BugTraq ID: 49957
Debian Security Information: DSA-2405 (Google Search)
HPdes Security Advisory: HPSBMU02748
HPdes Security Advisory: HPSBOV02822
HPdes Security Advisory: SSRT100772
HPdes Security Advisory: SSRT100966
SuSE Security Announcement: SUSE-SU-2011:1229 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:0243 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:0248 (Google Search)
XForce ISS Database: apache-modproxy-information-disclosure(70336)
Common Vulnerability Exposure (CVE) ID: CVE-2011-3192
BugTraq ID: 49303
CERT/CC vulnerability note: VU#405811
Cisco Security Advisory: 20110830 Apache HTTPd Range Header Denial of Service Vulnerability
HPdes Security Advisory: HPSBMU02766
HPdes Security Advisory: HPSBMU02776
HPdes Security Advisory: HPSBUX02702
HPdes Security Advisory: SSRT100606
HPdes Security Advisory: SSRT100624
HPdes Security Advisory: SSRT100852
SuSE Security Announcement: SUSE-SU-2011:1000 (Google Search)
SuSE Security Announcement: SUSE-SU-2011:1007 (Google Search)
SuSE Security Announcement: SUSE-SU-2011:1010 (Google Search)
SuSE Security Announcement: SUSE-SU-2011:1216 (Google Search)
SuSE Security Announcement: openSUSE-SU-2011:0993 (Google Search)
XForce ISS Database: apache-http-byterange-dos(69396)
CopyrightCopyright (c) 2012 E-Soft Inc.

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.

© 1998-2022 E-Soft Inc. All rights reserved.