Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1834-1] New apache2 packages fix denial of service (1/6

    From Stefan Fritsch@1:229/2 to All on Wed Jul 15 21:10:08 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1834 [email protected] http://www.debian.org/security/ Stefan Fritsch
    July 15, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : apache2
    Vulnerability : denial of service
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2009-1890 CVE-2009-1891

    A denial of service flaw was found in the Apache mod_proxy module when
    it was used as a reverse proxy. A remote attacker could use this flaw
    to force a proxy process to consume large amounts of CPU time. This
    issue did not affect Debian 4.0 "etch". (CVE-2009-1890)

    A denial of service flaw was found in the Apache mod_deflate module.
    This module continued to compress large files until compression was
    complete, even if the network connection that requested the content
    was closed before compression completed. This would cause mod_deflate
    to consume large amounts of CPU if mod_deflate was enabled for a large
    file. A similar flaw related to HEAD requests for compressed content
    was also fixed. (CVE-2009-1891)

    For the stable distribution (lenny), these problems have been fixed in
    version 2.2.9-10+lenny4.

    The oldstable distribution (etch), these problems have been fixed in
    version 2.2.3-4+etch9.

    For the testing distribution (squeeze) and the unstable distribution
    (sid), these problems will be fixed in version 2.2.11-7.

    This advisory also provides updated apache2-mpm-itk packages which
    have been recompiled against the new apache2 packages.

    Updated packages for the s390 and mipsel architectures are not
    included yet. They will be released as soon as they become available.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.2.3-4+etch9.diff.gz
    Size/MD5 checksum: 127065 2705ba251cdd2e979ce85099b4548848
    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.2.3-4+etch9.dsc
    Size/MD5 checksum: 1068 5090ccfce8dc2e193a0200a5046fc0c2
    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01-2+etch3.diff.gz
    Size/MD5 checksum: 12705 7327720850092af23dae939c8b6e0268
    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01.orig.tar.gz
    Size/MD5 checksum: 29071 63daaf8812777aacfd5a31ead4ff0061
    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.2.3.orig.tar.gz
    Size/MD5 checksum: 6342475 f72ffb176e2dc7b322be16508c09f63c
    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01-2+etch3.dsc
    Size/MD5 checksum: 676 3823620d6958a99e0d9bf8d54172071e

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/a/apache2/apache2-src_2.2.3-4+etch9_all.deb
    Size/MD5 checksum: 6666600 863bd8f5274dcca2b348ddfb455f1e98
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-perchild_2.2.3-4+etch9_all.deb
    Size/MD5 checksum: 274258 632e77496c06ac55702187083210c5bd
    http://security.debian.org/pool/updates/main/a/apache2/apache2-doc_2.2.3-4+etch9_all.deb
    Size/MD5 checksum: 2243400 3c97cd0ed50e13730082455509ccf2ea
    http://security.debian.org/pool/updates/main/a/apache2/apache2_2.2.3-4+etch9_all.deb
    Size/MD5 checksum: 41428 765f1df6239124b257a17373ec12a25c

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01-2+etch3_alpha.deb
    Size/MD5 checksum: 184750 a5ab12e5997c22cc5384f4dd57039bf0
    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.2.3-4+etch9_alpha.deb
    Size/MD5 checksum: 406786 9327ff1f134980e38e8af0a9bd333744
    http://security.debian.org/pool/updates/main/a/apache2/apache2-utils_2.2.3-4+etch9_alpha.deb
    Size/MD5 checksum: 345748 e6aa3a131e39ea0da098cd68e769ca7b
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.2.3-4+etch9_alpha.deb
    Size/MD5 checksum: 407410 1f8fa482173f33fbf635c4d4b622d6dd
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.2.3-4+etch9_alpha.deb
    Size/MD5 checksum: 449496 f4bb6824e49f741d853b80c6cd1c34be
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.2.3-4+etch9_alpha.deb
    Size/MD5 checksum: 444670 26e6f91f3f21c9c3ce178abff526f8d6
    http://security.debian.org/pool/updates/main/a/apache2/apache2.2-common_2.2.3-4+etch9_alpha.deb
    Size/MD5 checksum: 1016848 234579bc27e5372455df962ae77da5ea
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-event_2.2.3-4+etch9_alpha.deb
    Size/MD5 checksum: 450004 8d41f42126489a657627549f3fd03236

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/a/apache2/apache2-prefork-dev_2.2.3-4+etch9_amd64.deb
    Size/MD5 checksum: 408082 af95e2d0f5daba30588d20bee6ea1374
    http://security.debian.org/pool/updates/main/a/apache2/apache2-threaded-dev_2.2.3-4+etch9_amd64.deb
    Size/MD5 checksum: 408766 8769e1922010d061afd64b917bf9ebfb
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-worker_2.2.3-4+etch9_amd64.deb
    Size/MD5 checksum: 436036 83d55a3ec28d1d2954d5c524ace972ed
    http://security.debian.org/pool/updates/main/a/apache2/apache2.2-common_2.2.3-4+etch9_amd64.deb
    Size/MD5 checksum: 999314 86e7fb785110434ba47a93ad08dfbb46
    http://security.debian.org/pool/updates/main/a/apache2/apache2-mpm-prefork_2.2.3-4+etch9_amd64.deb
    Size/MD5 checksum: 432016 34bea3d8a903690047c0ce17dff9d0a8
    http://security.debian.org/pool/updates/main/a/apache2-mpm-itk/apache2-mpm-itk_2.2.3-01-2+etch3_amd64.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sun Jun 7 01:30:12 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Sat Jun 6 23:27:30 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Fri Jun 5 17:52:51 2026
      from Sheboygan, Wi via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 156:58:50
    Calls: 12,093
    Calls today: 1
    Files: 15,000
    Messages: 6,517,746

© >>> Magnum BBS <<<, 2026