Mandrake Linux Security Advisory : apache (MDKSA-2000:060-2)

medium Nessus Plugin ID 61847

Synopsis

The remote Mandrake Linux host is missing one or more security updates.

Description

The Apache web server comes with a module called mod_rewrite which is used to rewrite URLs presented by the client prior to further processing. There is a flaw in the mod_rewrite logic that allows an attacker to view arbitrary files on the server system if they contain regular expression references. All Linux-Mandrake users using Apache are encouraged to upgrade to these updated versions that fix this flaw.

The Apache package for 7.1 had a problem with improper permissions on the suexec wrapper which prevented it from running if the apache-suexec package was installed. As well, the uninstall script would exit with errors. Both issues are fixed. The new md5 checksums are listed below.

Update :

The permissions on the -14mdk apache-suexec package were still incorrect. While some CGI scripts would perform, others would not due to the permissions being 4700 and not 4711. The -15mdk RPMs for 7.1 fix this issue.

Solution

Update the affected apache, apache-devel and / or apache-suexec packages.

Plugin Details

Severity: Medium

ID: 61847

File Name: mandrake_MDKSA-2000-060.nasl

Version: 1.6

Type: local

Published: 9/6/2012

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.7

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:apache, p-cpe:/a:mandriva:linux:apache-devel, p-cpe:/a:mandriva:linux:apache-suexec, cpe:/o:mandrakesoft:mandrake_linux:6.0, cpe:/o:mandrakesoft:mandrake_linux:6.1, cpe:/o:mandrakesoft:mandrake_linux:7.0, cpe:/o:mandrakesoft:mandrake_linux:7.1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 10/18/2000

Reference Information

CVE: CVE-2000-0913

MDKSA: 2000:060-2