Solution
Please Install the Updated Packages.
Insight
Multiple vulnerabilities has been found and corrected in apache (ASF HTTPD):
Insecure handling of LD_LIBRARY_PATH was found that could lead to the current working directory to be searched for DSOs. This could allow a local user to execute code as root if an administrator runs apachectl from an untrusted directory (CVE-2012-0883).
Possible XSS for sites which use mod_negotiation and allow untrusted uploads to locations which have MultiViews enabled (CVE-2012-2687).
The updated packages have been upgraded to the latest 2.2.23 version which is not vulnerable to these issues.
Update:
Packages for Mandriva Linux 2011 is also being provided.
Affected
apache on Mandriva Linux 2011.0
Severity
Classification
-
CVE CVE-2012-0883, CVE-2012-2687 -
CVSS Base Score: 6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities