Bug 736690 (CVE-2011-3348)
Summary: | CVE-2011-3348 httpd: mod_proxy_ajp remote temporary DoS | |||
---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> | |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | |
Status: | CLOSED ERRATA | QA Contact: | ||
Severity: | medium | Docs Contact: | ||
Priority: | medium | |||
Version: | unspecified | CC: | ddevaraj, jclere, jentrena, jorton, pcheung, security-response-team, vdanen, weli, williama_lovaton | |
Target Milestone: | --- | Keywords: | Security | |
Target Release: | --- | |||
Hardware: | All | |||
OS: | Linux | |||
Whiteboard: | ||||
Fixed In Version: | httpd 2.2.21 | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | ||
Clone Of: | ||||
: | 1055563 (view as bug list) | Environment: | ||
Last Closed: | 2012-05-07 19:34:53 UTC | Type: | --- | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | 738961, 743901, 746695, 746696, 746697 | |||
Bug Blocks: | 736705 |
Description
Tomas Hoger
2011-09-08 12:31:40 UTC
(In reply to comment #0) > Upstream commit: > http://svn.apache.org/viewvc?view=revision&revision=1166551 Replaced by: http://svn.apache.org/viewvc?view=revision&revision=1166657 Public now via upstream httpd release 2.2.21: http://httpd.apache.org/security/vulnerabilities_22.html#2.2.21 http://www.apache.org/dist/httpd/CHANGES_2.2.21 http://mail-archives.apache.org/mod_mbox/httpd-announce/201109.mbox/%3C4E704A90.2000200@apache.org%3E Statement: This issue did not affect the versions of httpd as shipped with Red Hat Enterprise Linux 4 and 5 as this flaw was introduced in version 2.2.12. External References: http://httpd.apache.org/security/vulnerabilities_22.html#2.2.21 This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2011:1391 https://rhn.redhat.com/errata/RHSA-2011-1391.html This issue has been addressed in following products: JBoss Enterprise Web Server 1.0.2 Via RHSA-2012:0543 https://rhn.redhat.com/errata/RHSA-2012-0543.html This issue has been addressed in following products: JBEWS 1.0 for RHEL 5 JBEWS 1.0 for RHEL 6 Via RHSA-2012:0542 https://rhn.redhat.com/errata/RHSA-2012-0542.html |