Debian Security Advisory

DSA-135-1 libapache-mod-ssl -- buffer overflow / DoS

Date Reported:
02 Jul 2002
Affected Packages:
Security database references:
In the Bugtraq database (at SecurityFocus): BugTraq ID 5084.
In Mitre's CVE dictionary: CVE-2002-0653.
More information:

The libapache-mod-ssl package provides SSL capability to the apache webserver. Recently, a problem has been found in the handling of .htaccess files, allowing arbitrary code execution as the web server user (regardless of ExecCGI / suexec settings), DoS attacks (killing off apache children), and allowing someone to take control of apache child processes - all through specially crafted .htaccess files.

This has been fixed in the libapache-mod-ssl_2.4.10-1.3.9-1potato2 package (for potato), and the libapache-mod-ssl_2.8.9-2 package (for woody). We recommend you upgrade as soon as possible.

Fixed in:

Debian GNU/Linux 2.2 (potato)

