Ubuntu 787-1: Apache vulnerabilities
Summary
Update Instructions
References
Package Information
==========================================================Ubuntu Security Notice USN-787-1 June 12, 2009 apache2 vulnerabilities CVE-2009-0023, CVE-2009-1191, CVE-2009-1195, CVE-2009-1955, CVE-2009-1956 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: apache2-common 2.0.55-4ubuntu2.5 apache2-mpm-perchild 2.0.55-4ubuntu2.5 apache2-mpm-prefork 2.0.55-4ubuntu2.5 apache2-mpm-worker 2.0.55-4ubuntu2.5 libapr0 2.0.55-4ubuntu2.5 Ubuntu 8.04 LTS: apache2-mpm-event 2.2.8-1ubuntu0.8 apache2-mpm-perchild 2.2.8-1ubuntu0.8 apache2-mpm-prefork 2.2.8-1ubuntu0.8 apache2-mpm-worker 2.2.8-1ubuntu0.8 apache2.2-common 2.2.8-1ubuntu0.8 Ubuntu 8.10: apache2-mpm-event 2.2.9-7ubuntu3.1 apache2-mpm-prefork 2.2.9-7ubuntu3.1 apache2-mpm-worker 2.2.9-7ubuntu3.1 apache2.2-common 2.2.9-7ubuntu3.1 Ubuntu 9.04: apache2-mpm-event 2.2.11-2ubuntu2.1 apache2-mpm-prefork 2.2.11-2ubuntu2.1 apache2-mpm-worker 2.2.11-2ubuntu2.1 apache2.2-common 2.2.11-2ubuntu2.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Matthew Palmer discovered an underflow flaw in apr-util as included in Apache. An attacker could cause a denial of service via application crash in Apache using a crafted SVNMasterURI directive, .htaccess file, or when using mod_apreq2. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-0023) Sander de Boer discovered that mod_proxy_ajp would reuse connections when a client closed a connection without sending a request body. A remote attacker could exploit this to obtain sensitive response data. This issue only affected Ubuntu 9.04. (CVE-2009-1191) Jonathan Peatfield discovered that Apache did not process Includes options correctly. With certain configurations of Options and AllowOverride, a local attacker could use an .htaccess file to override intended restrictions and execute arbitrary code via a Server-Side-Include file. This issue affected Ubuntu 8.04 LTS, 8.10 and 9.04. (CVE-2009-1195) It was discovered that the XML parser did not properly handle entity expansion. A remote attacker could cause a denial of service via memory resource consumption by sending a crafted request to an Apache server configured to use mod_dav or mod_dav_svn. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-1955) C. Michael Pilato discovered an off-by-one buffer overflow in apr-util when formatting certain strings. For big-endian machines (powerpc, hppa and sparc in Ubuntu), a remote attacker could cause a denial of service or information disclosure leak. All other architectures for Ubuntu are not considered to be at risk. This issue only affected Ubuntu 6.06 LTS. (CVE-2009-1956) Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 123724 00519250c6506489a6c39936925e568e Size/MD5: 1156 20f5954982f1615b73eb8d180069a55e Size/MD5: 6092031 45e32c9432a8e3cf4227f5af91b03622 Architecture independent packages: Size/MD5: 2125174 6ee0433b3d2fbf33c6514599bcfe047b amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 833636 0e14aa964bbfd817e44d0c6517bb0d03 Size/MD5: 228830 db8dee716fa4906b74138b6efbb8f52a Size/MD5: 223844 4277481db3a7217319f1fb4bc9a9df5b Size/MD5: 228456 d4e86af7ea2751f782c9f81504c899e9 Size/MD5: 171972 16352ec1565ada8204deb4d4aa7e460d Size/MD5: 172750 3e8ad9cc35d7a6b8a97d320610c79024 Size/MD5: 94816 f251b0a95e6554c4d6e686b5a6f9132f Size/MD5: 36864 7d4f1abc24314c8f1682d0bc5a727882 Size/MD5: 286326 240a6f25212bacab7cef3af8218ef235 Size/MD5: 144886 20ce4e07cf33f50c279aa57876da241d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 786858 9086ee9622bf2f6299d521751b7984cc Size/MD5: 203506 903fda93a0084cbeb163c06823a2424c Size/MD5: 199358 ab3b3082cdd4537004f92f0cf9d67331 Size/MD5: 202902 69f2874396cc0895e05b369f9806e34c Size/MD5: 171980 2eca5344df9c14e289ea045633d33439 Size/MD5: 172750 46fc5dc35f23b087f1438f88b1a0d082 Size/MD5: 92760 065675c9336669192e09604adbec77d1 Size/MD5: 36866 c95b2e1cd3b70a2714c6a1a12a780038 Size/MD5: 262324 e3598aad5a3be422319e509b1fc17386 Size/MD5: 132808 c36dc81bbc044508961082c730659356 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 859676 46bd81028dcf7be9e41770dd11af37ae Size/MD5: 220862 b1f08076334f064ca0bd69dd599aa59d Size/MD5: 216506 57bd719b0a500747320db3c77350a97e Size/MD5: 220360 8451b10349e241687954b916a31e9680 Size/MD5: 171978 37abe43c6f3bb7ff514ec55b7b23c2c7 Size/MD5: 172754 c2b337ff66a86c0ad67a02667e63618a Size/MD5: 104538 1d91ed96d5f569ad59f07767dc7aadbe Size/MD5: 36866 605992b543ab267be7fff50c028b96eb Size/MD5: 281870 40933a88468e6a97a06828e24a430ad5 Size/MD5: 141986 ad0ee1e4188fa56dfc23d217b31b9e4a sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 803992 df7406ce6b8c2037e17eab5aba1fd947 Size/MD5: 211278 8c29e978a758d2a885048bc8e8529be7 Size/MD5: 206812 9f549366fdc0481d40bc6123ddbb3d91 Size/MD5: 210522 27dadfb40c60d99aa5570daaa05f5ba6 Size/MD5: 171976 aa9dd20fbb4eea6a4e0e0fa20538dad7 Size/MD5: 172756 480182b02dc98f8e86119452cf4dc031 Size/MD5: 93858 6f000d7b9a0f48de4e22a39f42e53fe8 Size/MD5: 36864 246e286fdb3f71b2b92c7cd783628dad Size/MD5: 268458 1c29830b1e623ff497ad20240861dc42 Size/MD5: 130780 46fbba05af3cdc1f39e73c2cca8716e1 Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 135718 b67b9e9cab0d958b01bf47433fcb299f Size/MD5: 1379 5f83de71908712e7fa37c517c6b9daf0 Size/MD5: 6125771 39a755eb0f584c279336387b321e3dfc Architecture independent packages: Size/MD5: 1928684 ccf0bbc4560b1d63f86681c5f91d38a5 Size/MD5: 72322 ffe7242eb5807cb4faf04af195824773 Size/MD5: 6254304 8dae450a6d4f8b948ae02dc3a165ad99 Size/MD5: 45252 0f62ab2a6205b27126c6c30ce0e8cc9d amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 252474 661f84e26a417adb6fb293cda4170146 Size/MD5: 248086 3196e11d84f523ef5e3409171eda56cf Size/MD5: 251832 ab128185607a1812fae9b7da809c5471 Size/MD5: 204994 5ce24738c1785a6ba05dd3e86337b1b3 Size/MD5: 205770 e8a688cfd6b67367c66c8ff0f2227e30 Size/MD5: 141084 da5c7a4aba57d0088a0122d81bbff9ad Size/MD5: 801788 0359700bb1d80e0e3a6fc1d8efe74d02 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 235446 0a61cd153337e09a91482b781fbf108e Size/MD5: 230978 c5a4a358ddfdba46ba19f8758614e85b Size/MD5: 234696 9a90bad413d4d46316f328776a2d950a Size/MD5: 205002 4cdf06a62da153d9b7d2cd6772a00c76 Size/MD5: 205766 36ee4a8ad7a8de250676d00aa02f9195 Size/MD5: 140046 a1adc8e4bdbf11a7c0856ecfbb333e08 Size/MD5: 754798 afea0689b2508b4d5bc5c41e19019eb0 lpia architecture (Low Power Intel Architecture): Size/MD5: 234958 4f05df526ebd1e4ab2b909b7e041e4c1 Size/MD5: 230616 ff72890c7622b3a291789006aa2099b4 Size/MD5: 234102 16fb9ac5b25ed2cc19729cfc48ad6014 Size/MD5: 204996 d8888829d11f62961a01fec4c0919403 Size/MD5: 205770 1c73843afed774da460e39b79ab332a7 Size/MD5: 140622 b1537a8a7a01aea78b0a67ba5ab6f84d Size/MD5: 748640 e2fc6fe941ec7a2238e57004816d3bb1 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 253568 1d84c15e686047e1eebd6812da6adcd9 Size/MD5: 248958 9e418948b0c7fed12e70e9ee07f193dc Size/MD5: 253052 e070abbfc3cd142234a30688320e5dbc Size/MD5: 205000 25018ddf577a7e66655b79775d67eb50 Size/MD5: 205782 9e78cbd7348964b8ab831e0482d3e41b Size/MD5: 157810 4b7d728303d38b057b043e96ee3ab7aa Size/MD5: 904910 359c25a1948ac2728e445082e60a7b44 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 236684 330ec61baee83347b37132f646264596 Size/MD5: 232578 11681fc7d5013b55d2e3f4e500797726 Size/MD5: 235912 cc331eab50a4ede19d0f88fd4fc0d00d Size/MD5: 204994 8b3d7bd0db0db66235a4f06f257108bf Size/MD5: 205762 134ff600abb6954b657a2fe8f9e5fa00 Size/MD5: 143256 90b0f6e9362aa3866e412a98e255b086 Size/MD5: 763970 c6bc1c87855dcc1e72a438a791d6952e Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 130909 ed59ca0fc5288b93fa2cb04af9aa2b7d Size/MD5: 1788 f80e4b56abc6bfc56125fc78aebab185 Size/MD5: 6396996 80d3754fc278338033296f0d41ef2c04 Architecture independent packages: Size/MD5: 2041562 05e984048a661ec86fe5051cab223b33 Size/MD5: 6537296 e9f14f43d75ec050e3d70cac84ba318f Size/MD5: 45016 f63b7b86981f837f780ae1a821c4b43d amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 254484 0e095f99d2e0e3ba925fff298a6f57f2 Size/MD5: 248678 88d8afa20352f18c8e5d810c6e474c97 Size/MD5: 253868 7ccad99f2fc89e63a394d4ad95335082 Size/MD5: 208050 187e0b01d15af23717d0d26771023c60 Size/MD5: 84018 9f56eeec1f836774e7e91f3cdfbf3ee5 Size/MD5: 82380 9085526c648b9d8656a2b7d2c7326655 Size/MD5: 209104 dcac98c57f63870120667d613939bbb0 Size/MD5: 147294 a6d9883304675907594ed1aab442d81a Size/MD5: 819450 a8562063da879ed20251894bd1e0746e i386 architecture (x86 compatible Intel/AMD): Size/MD5: 240916 d05183c57521d23cf2281e2d9589c8c3 Size/MD5: 235528 b4908cd5d4b70f8ede12cf7b6e103223 Size/MD5: 240188 63c83e128a121c7c9c188b02eb59edcb Size/MD5: 208056 01f550eb1d15495d5d896d522ade4396 Size/MD5: 83470 97a20ccf92b43e4b32d182a128b22072 Size/MD5: 81868 4f3ef154558c65db2daf74f940779760 Size/MD5: 209110 b291e921de088d2efabf33e4cd35c99e Size/MD5: 146130 6ea24f8ff6bd7a5921c575b402bc2d32 Size/MD5: 777780 e598efbc86f7a1d7e9675deb6a237e4c lpia architecture (Low Power Intel Architecture): Size/MD5: 237796 38656143c16829748990fe35c2618b95 Size/MD5: 232460 9e20d4fb43009cba2133ecb7d0fe5684 Size/MD5: 237088 2ca48410f10f3e9b800e1c131edc8192 Size/MD5: 208070 02f11c5c6874f97a7e737030cd22d333 Size/MD5: 83412 fb1c3db7a5c0a6c25d842600e7166584 Size/MD5: 81840 43514a92cf231cb8e57a21448b4183df Size/MD5: 209122 7fd0dd58cbc286cf730fd7e3be8e5329 Size/MD5: 145818 92e9731915cc84e775fd303142186bad Size/MD5: 765882 179c476b74f6d593dde3a53febb5684e powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 261012 4706fe724bc8469e9693983b6e5cb542 Size/MD5: 255554 70580bb638d16932a6376e8e593f012a Size/MD5: 260364 1703559523a2765da24f8cb748992345 Size/MD5: 208078 f538ef7ed95defc239ecc498b898efaa Size/MD5: 84104 5f127b51e775dfe285eb8d5c448ff752 Size/MD5: 82462 960f91f842e5fc0eea867a14290334bc Size/MD5: 209116 13c8662a31d5fdef85ca3ac3637a8689 Size/MD5: 160562 4734c80d99389ab39d553aee59fa6ff7 Size/MD5: 925502 4400f5d7e9411b679249a34551d34b83 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 246136 2132add596f6b3cde962f2f0d7fc31ad Size/MD5: 240772 0e3e5f9de7a877c3dfe0a9b8167a6c53 Size/MD5: 245500 e7f1c5af7f735a3f10b3be90df71fc0e Size/MD5: 208076 ec4d3e98ca11376db2b9d8fd6d884b60 Size/MD5: 83642 2b61d89fe5f802d75289ceb000d5725b Size/MD5: 82022 07d39ee448a55ebcfe25194bfff62929 Size/MD5: 209124 2c3a8b2f2a2863350baec615cf5e3643 Size/MD5: 150470 ab783bdd5be74dd06e791aba78113be0 Size/MD5: 783186 bdfe2bc8f54cb65d38cb96038ceddb09 Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 134781 129b768f9b402dbab2177edc6cffc1b4 Size/MD5: 1795 f6124369956b88a09f1786687e187af8 Size/MD5: 6806786 03e0a99a5de0f3f568a0087fb9993af9 Architecture independent packages: Size/MD5: 2218488 ab645fa9c67940ee29934317f2383bec Size/MD5: 46084 7be24aa4d43f4d55e36e95e831e04fcb Size/MD5: 6945842 a0742af1b44b20a35c24cca56a0b59a0 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 258410 de4fb0f20ec133b06d7464a9ea80866d Size/MD5: 252600 96fc657175db7e0958b2aff2884787ce Size/MD5: 257804 d7089118239d000dbc68ab95bfd271dd Size/MD5: 212740 7fd9950428d290b6b3aee7278b20801b Size/MD5: 213712 67b090ab9856a9812df4b8b8ef66dccb Size/MD5: 150594 58993a2d2fae87fafecfab2bdc06b521 Size/MD5: 824406 af48b8490ac13329fd761d279d16b22b Size/MD5: 87250 6ef1e665dab19ae16a0a3a8d8b441f52 Size/MD5: 85530 a104eeb1d1114e57ad91f3f646ff8e2d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 244922 1fff6a156eb80ae9edf1965b205215d3 Size/MD5: 239444 a61af2e80ff7a7d397478396968efa7a Size/MD5: 244292 a80eae6d7f5c060cfa12950759433a4f Size/MD5: 212748 684eac3801bf1650ca4662cc354ef95e Size/MD5: 213718 d9c889bad26894b386934ca35a1e1379 Size/MD5: 149484 755cb6034670192a724407b37e7cb355 Size/MD5: 783390 b6fa516c19bb6d82776347dd3e940094 Size/MD5: 86630 d20a788cb4ac4eb1315ef0739e015214 Size/MD5: 85030 96d33de27e43def58d919d6cf9660d68 lpia architecture (Low Power Intel Architecture): Size/MD5: 241826 7f57b43f10b1c3c9ed8936c1fce4b13c Size/MD5: 236352 bb836a54002a4245cae4c26f24b9f7c0 Size/MD5: 241204 6b7073a4e777394416240b7da64d4036 Size/MD5: 212724 abfa6f5688aacdb6ceab53d14bf93f0e Size/MD5: 213702 fdd3ddcf889bc8cbe5625e3dd8959bff Size/MD5: 149198 e6eae8fa571b6bf17b98aeb232d22e4d Size/MD5: 772602 612374c962f685533d55e821f2748828 Size/MD5: 86576 13c229e63eb2011c9a74f1eaea7bacb6 Size/MD5: 84988 e70529926eb88e73ee1f7f06f73ef414 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 265034 8244078723fb247d4cddfd0376374b8d Size/MD5: 259822 a81eb991f88dbb4cb6b374ea6315f0ba Size/MD5: 264502 512f211e4bc233c8351b620fb9e27fa4 Size/MD5: 212754 f284e4114d049c15632ac08ddc6ddc2d Size/MD5: 213728 c8caee451ecefb8d856412ebcaaff627 Size/MD5: 163892 c7b9a87427478a72be106c8de950de13 Size/MD5: 931558 3280b97e8ab35c15b6b9f0192c60895b Size/MD5: 87326 da229fa04d2536679c0cdd7a4447929b Size/MD5: 85592 72dd8fe34d798e65b77bcb5b3e40122d sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 250148 f903b1decc466013c618579f36e30ec4 Size/MD5: 244470 66c2b05cf6585a40346c341d1b3ba3b2 Size/MD5: 249532 50f65920d24048ba1e7444d7bf42e9bd Size/MD5: 212752 100150fe2cc4ffeb96b41965995493bd Size/MD5: 213718 16c269440c2cba44360cd49c89463ece Size/MD5: 153740 8531a5268c9ead29583a2102f1ee929b Size/MD5: 788532 415364037e428a8d1dcf3565fefced36 Size/MD5: 86830 662ac6195c360fbf5416f9fbefde46ac Size/MD5: 85124 585acf45b85fe68308c459076f7d6d93