Apache 1.3.x proxy hole
From: Joe Hamelin (nethead_at_gmail.com)
Date: 07/07/04
- Previous message: Dan Dexter: "RE: I need a "brain dead" simple, web-based, web page builder for individual users."
- Next in thread: Uwe Doering: "Re: Apache 1.3.x proxy hole"
- Reply: Uwe Doering: "Re: Apache 1.3.x proxy hole"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Wed, 7 Jul 2004 11:10:00 -0700 To: freebsd-isp@freebsd.org
Techworld is reporting that: "The bug affects Apache 1.3.x
installations configured to act as proxy servers, which relay requests
between a Web browser and the Internet. When a vulnerable server
connects to a malicious site, a specially-crafted packet can be used
to exploit the vulnerability, according to security researcher Georgi
Guninski, who has publicly released exploit code."
http://bsdnews.com/view_story.php3?story_id=4628
http://www.techworld.com/opsys/news/index.cfm?newsid=1814&page=1&pagepos=2
Does anyone know of a FreeBSD patch for this out yet?
-- Joe Hamelin Edmonds, WA, US _______________________________________________ freebsd-isp@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-isp To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"
- Previous message: Dan Dexter: "RE: I need a "brain dead" simple, web-based, web page builder for individual users."
- Next in thread: Uwe Doering: "Re: Apache 1.3.x proxy hole"
- Reply: Uwe Doering: "Re: Apache 1.3.x proxy hole"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|