Bug 517936 - httpd/SSL memory leak
Summary: httpd/SSL memory leak
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: httpd
Version: 11
Hardware: All
OS: Linux
low
medium
Target Milestone: ---
Assignee: Joe Orton
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-08-18 02:12 UTC by T. Howell-Cintron
Modified: 2009-08-18 10:21 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-08-18 10:21:15 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description T. Howell-Cintron 2009-08-18 02:12:45 UTC
Description of problem:
The latest version of Apache appears to be afflicted with a bug that allows remote attackers to cause a denial-of-service via multiple calls.  This is CVE-2008-1678.

Version-Release number of selected component (if applicable):
  httpd-2.2.11-8.i586

Additional info:
RHEL5 has a security advisory and updated packages under RHSA-2009:1075-1.  These packages also address the Options bug reported in CVE-2009-1195.

Comment 1 Joe Orton 2009-08-18 10:21:15 UTC
CVE-2008-1678 was fixed in 2.2.9.

2.2.13 updates are being built which will fix CVE-2009-1195 et al.


Note You need to log in before you can comment on or make changes to this bug.