Gentoo Security Advisory GLSA 200509-12 (Apache)

Summary
The remote host is missing updates announced in advisory GLSA 200509-12.
Solution
All mod_ssl users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=net-www/mod_ssl-2.8.24' All Apache 2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=net-www/apache-2.0.54-r15' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200509-12 http://bugs.gentoo.org/show_bug.cgi?id=103554 http://bugs.gentoo.org/show_bug.cgi?id=104807
Insight
mod_ssl and Apache are vulnerable to a restriction bypass and a potential local privilege escalation.