Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1816-1] New apache2 packages fix privilege escalation (

    From Stefan Fritsch@1:229/2 to All on Tue Jun 16 22:00:15 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1816-1 [email protected] http://www.debian.org/security/ Stefan Fritsch
    June 16, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : apache2
    Vulnerability : insufficient security check
    Problem type : local
    Debian-specific: no
    CVE Id(s) : CVE-2009-1195

    It was discovered that the Apache web server did not properly handle
    the "Options=" parameter to the AllowOverride directive:

    In the stable distribution (lenny), local users could (via .htaccess)
    enable script execution in Server Side Includes even in configurations
    where the AllowOverride directive contained only
    Options=IncludesNoEXEC.

    In the oldstable distribution (etch), local users could (via
    .htaccess) enable script execution in Server Side Includes and CGI
    script execution in configurations where the AllowOverride directive
    contained any "Options=" value.

    For the stable distribution (lenny), this problem has been fixed in
    version 2.2.9-10+lenny3.

    The oldstable distribution (etch), this problem has been fixed in
    version 2.2.3-4+etch8.

    For the testing distribution (squeeze) and the unstable distribution
    (sid), this problem will be fixed in version 2.2.11-6.

    This advisory also provides updated apache2-mpm-itk packages which
    have been recompiled against the new apache2 packages (except for the
    s390 architecture where updated packages will follow shortly).

    We recommend that you upgrade your apache2 packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01-2+etch2.dsc
    Size/MD5 checksum: 676 60ae12c222f55bfb4d8741409f59807c
    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.2.3-4+etch8.diff.gz
    Size/MD5 checksum: 126164 0f93fb2fea38521c4b2ac9411167e5af
    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01.orig.tar.gz
    Size/MD5 checksum: 29071 63daaf8812777aacfd5a31ead4ff0061
    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01-2+etch2.diff.gz
    Size/MD5 checksum: 12678 5019486d10734d7286f22e12da18764a
    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.2.3.orig.tar.gz
    Size/MD5 checksum: 6342475 f72ffb176e2dc7b322be16508c09f63c
    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.2.3-4+etch8.dsc
    Size/MD5 checksum: 1068 c99d93533c181ea28ccdb61df0464319

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.2.3-4+etch8_all.deb
    Size/MD5 checksum: 274190 321a2158857f223fcb825d4b286ba06b
    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.2.3-4+etch8_all.deb
    Size/MD5 checksum: 41386 1539cf468ace0922e31c6071dafd3813
    http://security.debian.org/pool/updates/main/a/apache2/apache2-src_2.2.3-4+etch8_all.deb
    Size/MD5 checksum: 6667722 f3242b4b8f5e5d33d9725a26d52a7300
    http://security.debian.org/pool/updates/main/a/apache2/apache2-doc_2.2.3-4+etch8_all.deb
    Size/MD5 checksum: 2243290 99eca5a57510d9cd19ff74dd1bbd4a8e

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.2.3-4+etch8_alpha.deb
    Size/MD5 checksum: 407346 02cbc40c73aa9252a6f9bebda4036c29
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.2.3-4+etch8_alpha.deb
    Size/MD5 checksum: 345688 05ffdd8778436fd2b1dee6bd7aadd3e0
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.2.3-4+etch8_alpha.deb
    Size/MD5 checksum: 406728 779b119a6c99f7f8e0d8930cc1a2b71b
    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01-2+etch2_alpha.deb
    Size/MD5 checksum: 184914 54d45ea160222856d8c4ed799d2965c9
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.2.3-4+etch8_alpha.deb
    Size/MD5 checksum: 449388 d925b5b3b9e271f4617a2efff0f3f143
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.2.3-4+etch8_alpha.deb
    Size/MD5 checksum: 444558 3ed40c6c95e4f25ef96906a636093249
    http://security.debian.org/pool/updates/main/a/apache2/apache2.2-common_2.2.3-4+etch8_alpha.deb
    Size/MD5 checksum: 1016788 3b4cac5858336e1553329e9a68d09be4
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-event_2.2.3-4+etch8_alpha.deb
    Size/MD5 checksum: 449926 317cb5e2564f48d8363090dee4e4e3c6

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.2.3-4+etch8_amd64.deb
    Size/MD5 checksum: 431928 7e2eb0a789bb596c5faa3727fcba90fb
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-event_2.2.3-4+etch8_amd64.deb
    Size/MD5 checksum: 436422 e91052469488153f4eba7f16c87ceaf9
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.2.3-4+etch8_amd64.deb
    Size/MD5 checksum: 408720 2c5044caf1e062d0d8b0e93ba93ac6f9
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.2.3-4+etch8_amd64.deb
    Size/MD5 checksum: 408032 cae76f94f7d177df301e9552aceb4d6d
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.2.3-4+etch8_amd64.deb
    Size/MD5 checksum: 435932 4ceb0c8c090b1f7bfbd8aa82d57c59cb
    http://security.debian.org/pool/updates/main/a/apache2/apache2.2-common_2.2.3-4+etch8_amd64.deb
    Size/MD5 checksum: 999246 219fc26ca8cd984bc438104d44605937
    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01-2+etch2_amd64.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 714
    Nodes: 16 (2 / 14)
    Uptime: 141:12:16
    Calls: 12,087
    Files: 14,998
    Messages: 6,517,442

© >>> Magnum BBS <<<, 2026