This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Apache updates/vulns

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Apache 2.4.10 released
- https://secunia.com/advisories/60170/
Release Date: 2014-07-21
Criticality: Moderately Critical
Where: From remote
Impact: DoS
Solution Status: Vendor Workaround
Software: Apache HTTP Server 2.4.x
CVE Reference(s):
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0117 - 4.3
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0118 - 4.3

- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0226 - 6.8

- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0231 - 5.0
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3523 - 5.0
… vulnerabilities are reported in versions 2.4.9 and prior…
Original Advisory: Apache:
- https://httpd.apache.org/security/vulnerabilities_24.html
"… security vulnerabilities fixed in released versions of Apache httpd 2.4…"

> https://httpd.apache.org/download.cgi#apache24
Stable Release - Latest Version: 2.4.10 (released 2014-07-21)

ZDI: http://zerodayinitiative.com/advisories/ZDI-14-239/

- http://news.netcraft.com/archives/2014/06/06/june-2014-web-server-survey.html
___

- http://www.securitytracker.com/id/1030615
CVE Reference: CVE-2014-0117, CVE-2014-0118, CVE-2014-0226, CVE-2014-0231, CVE-2014-3523
July 21 2014
Impact: Denial of service via network, Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 2.4.10 …
 

:ph34r:

FYI…

Apache HttpComponents client updated
- https://mail-archives.apache.org/mod_mbox/www-announce/201408.mbox/CVE-2014-3577
18 Aug 2014 - "Apache HttpComponents (prior to revision 4.3.5/4.0.2) may be susceptible to a 'Man in the Middle Attack' due to a flaw in the default hostname verification during SSL/TLS when a specially crafted server side certificate is used.
Background: During an SSL connection (https) the client verifies the hostname in the URL against the hostname as encoded in the servers certificate (CN, subjectAlt fields). This is to ensure that the client connects to the 'real' server, as opposed to something in middle (man in the middle) that may compromise end to end confidentiality and integrity…"

> https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3577 - 5.8
Last revised: 08/21/2014
 

:ph34r: