Red Hat: mod_ssl minor vulnerability
Summary
Summary
The mod_ssl module provides strong cryptography for the Apache Webserver via the Secure Sockets Layer (SSL) and Transport Layer Security(TLS) protocols.A format string issue was discovered in mod_ssl for Apache 1.3 which can betriggered if mod_ssl is configured to allow a client to proxy to remote SSLsites. In order to exploit this issue, a user who is authorized to useApache as a proxy would have to attempt to connect to a carefully craftedhostname via SSL. The Common Vulnerabilities and Exposures project(cve.mitre.org) has assigned the name CAN-2004-0700 to this issue.Users of mod_ssl should upgrade to this updated package, which contains abackported patch to correct this issue.
Solution
Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:
up2date
For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:
http://www.redhat.com/docs/manuals/enterprise/
5. Bug IDs fixed (http://bugzilla.redhat.com/ for more info):
128170 - CAN-2004-0700 mod_ssl format string vulnerability
6. RPMs required:
Red Hat Enterprise Linux AS (Advanced Server) version 2.1:
SRPMS:
209d559b50b81524606203cada5c4b68 mod_ssl-2.8.12-6.src.rpm
i386:
ecb068475e82644cfa0ed913b3bd1dc2 mod_ssl-2.8.12-6.i386.rpm
ia64:
483397e046e50c433d85bd74c3f8d7e4 mod_ssl-2.8.12-6.ia64.rpm
Red Hat Linux Advanced Workstation 2.1:
SRPMS:
209d559b50b81524606203cada5c4b68 mod_ssl-2.8.12-6.src.rpm
ia64:
483397e046e50c433d85bd74c3f8d7e4 mod_ssl-2.8.12-6.ia64.rpm
Red Hat Enterprise Linux ES version 2.1:
SRPMS:
209d559b50b81524606203cada5c4b68 mod_ssl-2.8.12-6.src.rpm
i386:
ecb068475e82644cfa0ed913b3bd1dc2 mod_ssl-2.8.12-6.i386.rpm
Red Hat Enterprise Linux WS version 2.1:
SRPMS:
209d559b50b81524606203cada5c4b68 mod_ssl-2.8.12-6.src.rpm
i386:
ecb068475e82644cfa0ed913b3bd1dc2 mod_ssl-2.8.12-6.i386.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
References
Package List
Topic
An updated mod_ssl package for Apache that fixes a format stringvulnerability is now available.
Topic
Relevant Releases Architectures
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64
Red Hat Linux Advanced Workstation 2.1 - ia64
Red Hat Enterprise Linux ES version 2.1 - i386
Red Hat Enterprise Linux WS version 2.1 - i386
Bugs Fixed