Slackware 10.0 / 10.1 / 10.2 / 8.1 / 9.0 / 9.1 / current : apache (SSA:2005-310-04)
Medium Nessus Plugin ID 20151
SynopsisThe remote Slackware host is missing a security update.
DescriptionNew apache packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current to fix potential security issues: * If a request contains both Transfer-Encoding and Content-Length headers, remove the Content-Length, mitigating some HTTP Request Splitting/Spoofing attacks. * Added TraceEnable [on|off|extended] per-server directive to alter the behavior of the TRACE method. It's hard to say how much real-world impact these have, as there's no more information about that in the announcement. The original Apache announement can be read here:
http://www.apache.org/dist/httpd/Announcement1.3.html Note that if you use mod_ssl, you will also need a new mod_ssl package. These have been provided for the same releases of Slackware.
SolutionUpdate the affected apache and / or mod_ssl packages.