Debian Security Advisory

DSA-2532-1 libapache2-mod-rpaf -- denial of service

Date Reported:
22 Aug 2012
Affected Packages:
libapache2-mod-rpaf
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 683984.
More information:

Sébastien Bocahu discovered that the reverse proxy add forward module for the Apache webserver is vulnerable to a denial of service attack through a single crafted request with many headers.

For the stable distribution (squeeze), this problem has been fixed in version 0.5-3+squeeze1.

For the testing distribution (wheezy) and unstable distribution (sid), this problem has been fixed in version 0.6-1.

We recommend that you upgrade your libapache2-mod-rpaf packages.