|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: Apache2 CSRF, XSS, Memory Corruption and Denial of Service Vulnerability | ||
|---|---|---|---|
| Product: | [openSUSE] openSUSE 10.3 | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Security | Assignee: | Sonja Krause-Harder <skh> |
| Status: | RESOLVED FIXED | QA Contact: | E-mail List <qa-bugs> |
| Severity: | Major | ||
| Priority: | P5 - None | CC: | security-team |
| Version: | Final | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| Whiteboard: | CVE-2007-6424: CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Bug Depends on: | |||
| Bug Blocks: | 355888 | ||
| Deadline: | 2008-02-11 | ||
|
Description
Ludwig Nussel
2008-01-11 16:14:51 UTC
Tracked in #355888 Date: Tue, 11 Mar 2008 14:41:27 +0000 From: Joe Orton <jorton@apache.org> To: Marcus Meissner <meissner@suse.de> Cc: security@httpd.apache.org, Sonja Krause-Harder <skh@suse.de> Subject: Re: CVE-2007-6420 Mail-Followup-To: Marcus Meissner <meissner@suse.de>, security@httpd.apache.org, Sonja Krause-Harder <skh@suse.de> User-Agent: Mutt/1.5.17 (2007-11-01) On Tue, Mar 11, 2008 at 02:19:52PM +0100, Marcus Meissner wrote: > I just stumbled across CVE-2007-6420, a cross site request forgery > in mod_proxy_balancer, and wonder if you plan to issue updates for > it, or at least have a statement on whether it will be fixed or not. We hadn't come up with any simple way to fix this type of issue when it came up originally, but it occurred to me recently that a simple fix is actually possible. I've posted this for review: http://marc.info/?l=apache-httpd-dev&m=120524545031664&w=2 joe (not yet final patch I guess) Fixed in 10.3, 10.2, 10.1/sles10, n/a for sles9 (2.2.x only). Packages submitted, further tracking in bug #355888. You have fixed CVE-2007-6421 and CVE-2007-6422. What about CVE-2007-6420 and CVE-2007-6424? CVE-2007-6423 only affects apache on windows (see original report and http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6423), the discussion about the fix for CVE-2007-6420 has resulted in a final patch yet and I didn't want to wait for that. s/has resulted/hasn't resulted/ I suppose. So I'll close this bug as fixed and open a new one with the pending issue so we don't forget about it. CVE-2007-6424: CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) |