Details
Apache did not honour the “SSLVerifyClient require” directive within a
directive “SSLVerifyClient optional”. This allowed clients to bypass
client certificate validation on servers with the above configuration.
(CAN-2005-2700)
Filip Sneppe discovered a Denial of Service vulnerability in the byte
range filter handler. By requesting certain large byte ranges, a
remote attacker could cause memory exhaustion in the server.
(CAN-2005-2728)
The updated libapache-mod-ssl also fixes two older Denial of Service
vulnerabilities: A format string error in the ssl_log() function which
could be exploited to crash the server (CAN-2004-0700), and a flaw in
the SSL cipher negotiation which could be exploited to terminate a
session (CAN-2004-0885). Please note that Apache 1.3 and
libapache-mod-ssl are not officially supported (they are in the
“universe”...
Apache did not honour the “SSLVerifyClient require” directive within a
directive “SSLVerifyClient optional”. This allowed clients to bypass
client certificate validation on servers with the above configuration.
(CAN-2005-2700)
Filip Sneppe discovered a Denial of Service vulnerability in the byte
range filter handler. By requesting certain large byte ranges, a
remote attacker could cause memory exhaustion in the server.
(CAN-2005-2728)
The updated libapache-mod-ssl also fixes two older Denial of Service
vulnerabilities: A format string error in the ssl_log() function which
could be exploited to crash the server (CAN-2004-0700), and a flaw in
the SSL cipher negotiation which could be exploited to terminate a
session (CAN-2004-0885). Please note that Apache 1.3 and
libapache-mod-ssl are not officially supported (they are in the
“universe” component of the Ubuntu archive).
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
5.04 hoary | apache2-mpm-worker – | ||
apache2-mpm-perchild – | |||
apache2-mpm-prefork – | |||
apache2-mpm-threadpool – | |||
libapache-mod-ssl – | |||
4.10 warty | apache2-mpm-worker – | ||
apache2-mpm-perchild – | |||
apache2-mpm-prefork – | |||
apache2-mpm-threadpool – | |||
libapache-mod-ssl – |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.