From d950fa39dbe16d164ed0cb8e3036fd5d0d896a4c Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 31 Oct 2017 15:47:53 +0000 Subject: gentoo resync : 31.10.2017 --- metadata/glsa/glsa-201710-32.xml | 77 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 77 insertions(+) create mode 100644 metadata/glsa/glsa-201710-32.xml (limited to 'metadata/glsa/glsa-201710-32.xml') diff --git a/metadata/glsa/glsa-201710-32.xml b/metadata/glsa/glsa-201710-32.xml new file mode 100644 index 000000000000..61324a61d421 --- /dev/null +++ b/metadata/glsa/glsa-201710-32.xml @@ -0,0 +1,77 @@ + + + + Apache: Multiple vulnerabilities + Multiple vulnerabilities have been found in Apache, the worst of + which may result in the loss of secrets. + + Apache + 2017-10-29 + 2017-10-29: 1 + 622240 + 624868 + 631308 + remote + + + 2.4.27-r1 + 2.4.27-r1 + + + +

The Apache HTTP server is one of the most popular web servers on the + Internet. +

+
+ +

Multiple vulnerabilities have been discovered in Apache. Please review + the referenced CVE identifiers for details. +

+
+ +

The Optionsbleed vulnerability can leak arbitrary memory from the server + process that may contain secrets. Additionally attackers may cause a + Denial of Service condition, bypass authentication, or cause information + loss. +

+
+ +

There is no known workaround at this time.

+
+ +

All Apache users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.27-r1" + +
+ + + CVE-2017-3167 + + + CVE-2017-3169 + + + CVE-2017-7659 + + + CVE-2017-7668 + + + CVE-2017-7679 + + + CVE-2017-9788 + + + CVE-2017-9789 + + + CVE-2017-9798 + + + jmbailey + jmbailey +
-- cgit v1.2.3