|
- - -------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200210-002 - - -------------------------------------------------------------------- PACKAGE : apache SUMMARY : shared memory scoreboard vulnerabilities EXPLOIT : local DATE : 2002-10-15 08:25 UTC - - -------------------------------------------------------------------- Apache HTTP Server contains a vulnerability in its shared memory scoreboard. Attackers who can execute commands under the Apache UID can either send a (SIGUSR1) signal to any process as root, in most cases killing the process, or launch a local denial of service (DoS) attack. Read the full advisory at http://www.idefense.com/advisory/10.03.02.txt SOLUTION It is recommended that all Gentoo Linux users who are running net-www/apache-1.3.26-r4 and earlier update their systems as follows: emerge rsync emerge apache emerge clean - - -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz - - --------------------------------------------------------------------