Summary
The remote host is missing updates announced in
advisory GLSA 200310-04.
Solution
It is recommended that all Gentoo Linux users who are running net-misc/apache 2.x upgrade:
# emerge sync
# emerge -pv '>=net-www/apache-2.0.48'
# emerge '>=net-www/apache-2.0.48'
# emerge clean
# /etc/init.d/apache2 restart
Please remember to update your config files in /etc/apache2 as --datadir has been changed to /var/www/localhost.
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200310-04 http://bugs.gentoo.org/show_bug.cgi?id=32271
Insight
Multiple stack-based buffer overflows in mod_alias and mod_rewrite can allow execution of arbitrary code and cause a denial of service, and a bug in the way mod_cgid handles CGI redirect paths could result in CGI output going to the wrong client.
Severity
Classification
-
CVE CVE-2003-0542, CVE-2003-0789 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities