Bug 130750

Summary: CAN-2004-0748 Apache child infinite loop
Product: [Fedora] Fedora Reporter: Mark J. Cox <mjc>
Component: httpdAssignee: Joe Orton <jorton>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 2CC: axel.thimm, redhat-bugzilla
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 2.0.51-2.7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2004-09-23 18:21:22 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
httpd-2.0.50-ssl_engine_io.patch none

Description Mark J. Cox 2004-08-24 09:43:57 UTC
Apache bug 29964 is "A remote attacker who forces an SSL connection to
be aborted in a particular state may cause an Apache child process to
enter an infinite loop, consuming CPU resources."  Fixed upstream
Aug11.  This doesn't affect mod_ssl with Apache 1.3

        CAN-2004-0748 Affects: FC1
        CAN-2004-0748 Affects: FC2

Comment 1 Robert Scheck 2004-09-02 17:13:55 UTC
Created attachment 103399 [details]
httpd-2.0.50-ssl_engine_io.patch

This patch should fix CAN-2004-0748, I currently can't find this patch it in
httpd-2.0.50-5...

Comment 2 Joe Orton 2004-09-03 08:20:33 UTC
There will be a 2.0.51 release soon so the current plan is to wait for
that and update to it, since neither of the mod_ssl issues look to be
exploitable.

Comment 3 Joe Orton 2004-09-15 15:35:56 UTC
2.0.51 is now released which fixes:

 * core: CAN-2004-0747
 * mod_dav_fs: CAN-2004-0809
 * mod_ssl: CAN-2004-0751, CAN-2004-0748

along with an apr-util update which fixes CAN-2004-0786.  Updates are
being prepared.


Comment 4 Joe Orton 2004-09-17 16:30:22 UTC
Packages are now available for FC2 from the testing repos:

http://www.redhat.com/archives/fedora-test-list/2004-September/msg00610.html

please post any feedback from testing these to this bug report.

Comment 5 Joe Orton 2004-09-23 18:21:22 UTC
2.0.51-2.7 updates issued, which include the fix for the CAN-2004-0811
regression in upstream 2.0.51.