Summary
The remote host is missing an update to apache
announced via advisory DSA 131-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20131-1
Insight
Mark Litchfield found a denial of service attack in the Apache web-server. While investigating the problem the Apache Software Foundation discovered that the code for handling invalid requests which use chunked encoding also might allow arbitrary code execution on 64 bit architectures.
This has been fixed in version 1.3.9-14.1 of the Debian apache package, as well as upstream versions 1.3.16 and 2.0.37. We strongly recommend that you upgrade your apache package immediately.
Severity
Classification
-
CVE CVE-2002-0392 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities