Closed
Bug 304502
Opened 19 years ago
Closed 19 years ago
mozilla.org's servers should update to at least Apache 2.0.53
Categories
(mozilla.org Graveyard :: Server Operations, task)
mozilla.org Graveyard
Server Operations
Tracking
(Not tracked)
RESOLVED
INVALID
People
(Reporter: Gijs, Assigned: justdave)
References
()
Details
Since 2.0.52 (which these servers seem to run, judging from the 404 reply...) the following security problems have been fixed: *) SECURITY: CAN-2004-0942 (cve.mitre.org) Fix for memory consumption DoS in handling of MIME folded request headers. [Joe Orton] *) SECURITY: CAN-2004-0885 (cve.mitre.org) mod_ssl: Fix a bug which allowed an SSLCipherSuite setting to be bypassed during an SSL renegotiation. PR 31505. [Hartmut Keil <Hartmut.Keil adnovum.ch>, Joe Orton] I'm not very knowledgeable in any related subjects, so I apologize in advance if this bug is filed in error (ie, the security problems shouldn't be exploitable considering the software run on the servers, or Red Hat has patched their httpd without updating the version). I'm filing this just in case it *is* important. Keeping normal severity until I am/others are sure that this is a critical problem.
Comment 1•19 years ago
|
||
Red Hat's Enterprise Linux support does tend to patch security holes without updating the version but wouldn't hurt to confirm it. Thanks for keeping an eye out for us. Switching to webtools security group
Group: security → webtools-security
| Assignee | ||
Comment 2•19 years ago
|
||
We are up-to-date. RedHat backports the security patches. We are currently running: httpd-2.0.52-12.1.ent * Fri Oct 29 2004 Joe Orton <jorton@redhat.com> 2.0.52-4.ent - add security fix for CVE CAN-2004-0942 (memory consumption DoS) * Thu Sep 28 2004 Joe Orton <jorton@redhat.com> 2.0.52-3 - mod_ssl: add security fix for CAN-2004-0885
Group: webtools-security
Status: UNCONFIRMED → RESOLVED
Closed: 19 years ago
Resolution: --- → INVALID
Updated•10 years ago
|
Product: mozilla.org → mozilla.org Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•