Debians sikkerhedsbulletin

DSA-021-1 apache -- usikker midlertidig fil-fejl, ikke-fungerende mod_rewrite

Rapporteret den:
26. jan 2001
Berørte pakker:
apache
Sårbar:
Ja
Referencer i sikkerhedsdatabaser:
I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 2182.
I Mitres CVE-ordbog: CVE-2001-0131.
Yderligere oplysninger:
WireX har fundet nogle forekomster af usikre åbninger af midlertidige filer i htdigest og htpasswd. Begge programmer installeres ikke setuid eller setgid og effekten skulle dermed være minimal. Apache-gruppen har frigivet en ny sikkerhedsfejlrettelse der retter en sårbarhed i mod_rewrite, som kan resultere i at en fjernangriber får adgang til vilkårlige filer på web-serveren.
Rettet i:

Debian 2.2 (potato)

Kildekode:
http://security.debian.org/dists/stable/updates/main/source/apache_1.3.9-13.2.diff.gz
http://security.debian.org/dists/stable/updates/main/source/apache_1.3.9-13.2.dsc
http://security.debian.org/dists/stable/updates/main/source/apache_1.3.9.orig.tar.gz
alpha:
http://security.debian.org/dists/stable/updates/main/binary-alpha/apache-common_1.3.9-13.2_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/apache-dev_1.3.9-13.2_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/apache_1.3.9-13.2_alpha.deb
arm:
http://security.debian.org/dists/stable/updates/main/binary-arm/apache-common_1.3.9-13.2_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/apache-dev_1.3.9-13.2_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/apache_1.3.9-13.2_arm.deb
i386:
http://security.debian.org/dists/stable/updates/main/binary-i386/apache-common_1.3.9-13.2_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/apache-dev_1.3.9-13.2_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/apache_1.3.9-13.2_i386.deb
m68k:
http://security.debian.org/dists/stable/updates/main/binary-m68k/apache-common_1.3.9-13.2_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/apache-dev_1.3.9-13.2_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/apache_1.3.9-13.2_m68k.deb
powerpc:
http://security.debian.org/dists/stable/updates/main/binary-powerpc/apache-common_1.3.9-13.2_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/apache-dev_1.3.9-13.2_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/apache_1.3.9-13.2_powerpc.deb
sparc:
http://security.debian.org/dists/stable/updates/main/binary-sparc/apache-common_1.3.9-13.2_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/apache-dev_1.3.9-13.2_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/apache_1.3.9-13.2_sparc.deb