Summary
The remote host is missing updates announced in
advisory GLSA 200409-21.
Solution
All Apache 2 users should upgrade to the latest version:
# emerge sync
# emerge -pv '>=net-www/apache-2.0.51'
# emerge '>=net-www/apache-2.0.51'
All mod_dav users should upgrade to the latest version:
# emerge sync
# emerge -pv '>=net-www/mod_dav-1.0.3-r2'
# emerge '>=net-www/mod_dav-1.0.3-r2'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200409-21 http://bugs.gentoo.org/show_bug.cgi?id=62626
http://bugs.gentoo.org/show_bug.cgi?id=63948
http://bugs.gentoo.org/show_bug.cgi?id=64145
Insight
Several vulnerabilities have been found in Apache 2 and mod_dav for Apache 1.3 which could allow a remote attacker to cause a Denial of Service or a local user to get escalated privileges.
Severity
Classification
-
CVE CVE-2004-0747, CVE-2004-0748, CVE-2004-0751, CVE-2004-0786, CVE-2004-0809 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities