Debian DSA-2237-1 : apr - denial of service
Medium Nessus Plugin ID 53900
SynopsisThe remote Debian host is missing a security-related update.
DescriptionA flaw was found in the APR library, which could be exploited through Apache HTTPD's mod_autoindex. If a directory indexed by mod_autoindex contained files with sufficiently long names, a remote attacker could send a carefully crafted request which would cause excessive CPU usage. This could be used in a denial of service attack.
SolutionUpgrade the apr packages and restart the apache2 server.
For the oldstable distribution (lenny), this problem has been fixed in version 1.2.12-5+lenny3.
For the stable distribution (squeeze), this problem has been fixed in version 1.4.2-6+squeeze1.