Säkerhetsbulletin från Debian

DSA-021-1 apache -- fel med osäkra temporärfiler, felaktig mod_rewrite

Rapporterat den:
2001-01-26
Berörda paket:
apache
Sårbara:
Ja
Referenser i säkerhetsdatabaser:
I Bugtraq-databasen (hos SecurityFocus): BugTraq-id 2182.
I Mitres CVE-förteckning: CVE-2001-0131.
Ytterligare information:
WireX har hittat några förekomster av osäker öppning av temporära filer i htdigest och htpasswd. Inget av programmen installeras som setuid eller setgid, och därför bör problemen som orsakas av detta vara minimala. Apachegruppen har släppt ytterligare en säkerhetsrättelse som rättar en sårbarhet i mod_rewrite vilken kunde få till resultat att en angripare utifrån kunde nå valfria filer på webbservern.
Rättat i:

Debian 2.2 (potato)

Källkod:
http://security.debian.org/dists/stable/updates/main/source/apache_1.3.9-13.2.diff.gz
http://security.debian.org/dists/stable/updates/main/source/apache_1.3.9-13.2.dsc
http://security.debian.org/dists/stable/updates/main/source/apache_1.3.9.orig.tar.gz
alpha:
http://security.debian.org/dists/stable/updates/main/binary-alpha/apache-common_1.3.9-13.2_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/apache-dev_1.3.9-13.2_alpha.deb
http://security.debian.org/dists/stable/updates/main/binary-alpha/apache_1.3.9-13.2_alpha.deb
arm:
http://security.debian.org/dists/stable/updates/main/binary-arm/apache-common_1.3.9-13.2_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/apache-dev_1.3.9-13.2_arm.deb
http://security.debian.org/dists/stable/updates/main/binary-arm/apache_1.3.9-13.2_arm.deb
i386:
http://security.debian.org/dists/stable/updates/main/binary-i386/apache-common_1.3.9-13.2_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/apache-dev_1.3.9-13.2_i386.deb
http://security.debian.org/dists/stable/updates/main/binary-i386/apache_1.3.9-13.2_i386.deb
m68k:
http://security.debian.org/dists/stable/updates/main/binary-m68k/apache-common_1.3.9-13.2_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/apache-dev_1.3.9-13.2_m68k.deb
http://security.debian.org/dists/stable/updates/main/binary-m68k/apache_1.3.9-13.2_m68k.deb
powerpc:
http://security.debian.org/dists/stable/updates/main/binary-powerpc/apache-common_1.3.9-13.2_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/apache-dev_1.3.9-13.2_powerpc.deb
http://security.debian.org/dists/stable/updates/main/binary-powerpc/apache_1.3.9-13.2_powerpc.deb
sparc:
http://security.debian.org/dists/stable/updates/main/binary-sparc/apache-common_1.3.9-13.2_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/apache-dev_1.3.9-13.2_sparc.deb
http://security.debian.org/dists/stable/updates/main/binary-sparc/apache_1.3.9-13.2_sparc.deb