Take the server survey

News

USN-160-2: Apache vulnerability

=========================================================== Ubuntu Security Notice USN-160-2 September 07, 2005 apache vulnerability CAN-2005-2088 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog) Ubuntu 5.04 (Hoary Hedgehog) The following packages are affected: apache-common The problem can be corrected by upgrading the affected package to version 1.3.31-6ubuntu0.8 (for Ubuntu 4.10), or 1.3.33-4ubuntu1 (for Ubuntu 5.04). In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: USN-160-1 fixed two vulnerabilities in the Apache 2 server. The old Apache 1 server was also vulnerable to one of the vulnerabilities (CAN-2005-2088). Please note that Apache 1 is not officially supported in Ubuntu (it is in the "universe" component of the archive). For reference, this is the relevant part of the original advisory: Watchfire discovered that Apache insufficiently verified the "Transfer-Encoding" and "Content-Length" headers when acting as an HTTP proxy. By sending a specially crafted HTTP request, a remote attacker who is authorized to use the proxy could exploit this to bypass web application firewalls, poison the HTTP proxy cache, and conduct cross-site scripting attacks against other proxy users. (CAN-2005-2088)