An unspecified flaw in Apache Traffic Server was fixed in versions 4.2.1.1 and 5.0.1. The fixed version is already in Fedora 20 and EPEL 7, leaving only Fedora 19 and EPEL 6 vulnerable. A patch for the older 3.x versions is available from the following: https://dist.apache.org/repos/dist/release/trafficserver/patches/trafficserver-3.2.5-CVE-2014-3525.diff References: http://mail-archives.apache.org/mod_mbox/trafficserver-users/201407.mbox/%3CBFCEC9C8-1BE9-4DCA-AF9C-B8FE798EEC07@yahoo-inc.com%3E
Created trafficserver tracking bugs for this issue: Affects: fedora-19 [bug 1133386] Affects: epel-6 [bug 1133387]