Ubuntu 6.06 LTS / 8.04 LTS / 8.10 / 9.04 : apache2 regression (USN-802-2)

Ubuntu Security Notice (C) 2009-2016 Canonical, Inc. / NASL script (C) 2009-2016 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing one or more security-related
patches.

Description :

USN-802-1 fixed vulnerabilities in Apache. The upstream fix for
CVE-2009-1891 introduced a regression that would cause Apache children
to occasionally segfault when mod_deflate is used. This update fixes
the problem.

We apologize for the inconvenience.

It was discovered that mod_proxy_http did not properly handle a large
amount of streamed data when used as a reverse proxy. A remote
attacker could exploit this and cause a denial of service via memory
resource consumption. This issue affected Ubuntu 8.04 LTS, 8.10 and
9.04. (CVE-2009-1890)

It was discovered that mod_deflate did not abort compressing
large files when the connection was closed. A remote
attacker could exploit this and cause a denial of service
via CPU resource consumption. (CVE-2009-1891).

Note that Tenable Network Security has extracted the preceding
description block directly from the Ubuntu security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 7.1
(CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C)
Public Exploit Available : true

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 40655 ()

Bugtraq ID:

CVE ID: CVE-2009-1890
CVE-2009-1891