Fedora 10 : httpd-2.2.14-1.fc10 (2009-12604)

This script is Copyright (C) 2009-2016 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

This update contains the latest stable release of Apache httpd. Three
security fixes are included, along with several minor bug fixes. A
flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handle session renegotiation. A
man-in-the-middle attacker could use this flaw to prefix arbitrary
plain text to a client's session (for example, an HTTPS connection to
a website). This could force the server to process an attacker's
request as if authenticated using the victim's credentials. This
update partially mitigates this flaw for SSL sessions to HTTP servers
using mod_ssl by rejecting client-requested renegotiation.
(CVE-2009-3555) Note: This update does not fully resolve the issue for
HTTPS servers. An attack is still possible in configurations that
require a server-initiated renegotiation A NULL pointer dereference
flaw was found in the Apache mod_proxy_ftp module. A malicious FTP
server to which requests are being proxied could use this flaw to
crash an httpd child process via a malformed reply to the EPSV or PASV
commands, resulting in a limited denial of service. (CVE-2009-3094) A
second flaw was found in the Apache mod_proxy_ftp module. In a reverse
proxy configuration, a remote attacker could use this flaw to bypass
intended access restrictions by creating a carefully-crafted HTTP
Authorization header, allowing the attacker to send arbitrary commands
to the FTP server. (CVE-2009-3095) See the upstream changes file for
further information: http://www.apache.org/dist/httpd/CHANGES_2.2.14

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

http://www.apache.org/dist/httpd/CHANGES_2.2.14
https://bugzilla.redhat.com/show_bug.cgi?id=521619
https://bugzilla.redhat.com/show_bug.cgi?id=522209
http://www.nessus.org/u?52dbbad6

Solution :

Update the affected httpd package.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 6.5
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Fedora Local Security Checks

Nessus Plugin ID: 43090 (fedora_2009-12604.nasl)

Bugtraq ID: 36254
36260
36935

CVE ID: CVE-2009-3094
CVE-2009-3095
CVE-2009-3555

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now