Summary
The remote host is missing an update as announced
via advisory SSA:2004-133-01.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=SSA:2004-133-01
Insight
New apache packages are available for Slackware 8.1, 9.0, 9.1, and -current to fix security issues. These include a possible denial-of-service attack as well as the ability to possible pipe shell escapes through Apache's errorlog (which could create an exploit if the error log is read in a terminal program that does not filter such escapes). We recommend that sites running Apache upgrade to the new Apache package.
More details about these issues may be found in the Common Vulnerabilities and Exposures (CVE) database:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0987 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0020 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0174 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0993
Severity
Classification
-
CVE CVE-2003-0020, CVE-2003-0987, CVE-2003-0993, CVE-2004-0174 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities