New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 3.6
SynopsisThe remote Scientific Linux host is missing one or more security updates.
DescriptionA flaw was found in the mod_proxy Apache module. An attacker in control of a Web server to which requests were being proxied could have caused a limited denial of service due to CPU consumption and stack exhaustion. (CVE-2008-2364)
A flaw was found in the mod_proxy_ftp Apache module. If Apache was configured to support FTP-over-HTTP proxying, a remote attacker could have performed a cross-site scripting attack. (CVE-2008-2939)
In addition, these updated packages fix a bug found in the handling of the 'ProxyRemoteMatch' directive in the Scientific Linux 4 httpd packages. This bug is not present in the Scientific Linux 3 or Scientific Linux 5 packages.
SolutionUpdate the affected packages.