Navigation Bar Top Applications Support Documentation Vendors Search Index Top Top

apache22 -- several vulnerability

Description:

Apache ChangeLog reports:

CVE-2009-1891: Fix a potential Denial-of-Service attack against mod_deflate or other modules.

CVE-2009-1195: Prevent the "Includes" Option from being enabled in an .htaccess file if the AllowOverride restrictions do not permit it.

CVE-2009-1890: Fix a potential Denial-of-Service attack against mod_proxy in a reverse proxy configuration.

CVE-2009-1191: mod_proxy_ajp: Avoid delivering content from a previous request which failed to send a request body.

CVE-2009-0023, CVE-2009-1955, CVE-2009-1956: The bundled copy of the APR-util library has been updated, fixing three different security issues which may affect particular configurations and third-party modules (was already fixed in 2.2.11_5).

References:

Affects:

portaudit: apache22 -- several vulnerability

Disclaimer: The data contained on this page is derived from the VuXML document, please refer to the the original document for copyright information. The author of portaudit makes no claim of authorship or ownership of any of the information contained herein.

If you have found a vulnerability in a FreeBSD port not listed in the database, please contact the FreeBSD Security Team. Refer to "FreeBSD Security Information" for more information.


Oliver Eikemeier <eik@FreeBSD.org>