Skip to main content

Alert GCSA-14025 - Vulnerabilita' in Apache HTTP Server


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

******************************************************************

   Alert ID : GCSA-14025
       Data : 25 luglio 2014
     Titolo : Vulnerabilita' in Apache HTTP Server

******************************************************************


:: Descrizione del problema

   E' stata rilasciata una nuova versione del server HTTP Apache
   con la quale vengono risolte varie vulnerabilita'.


:: Software interessato

   Apache HTTP Server 2.4.9 e precedenti


:: Impatto

   Denial of service


:: Soluzioni

   Aggiornare Apache alla versione 2.4.10
   http://httpd.apache.org/download.cgi


:: Riferimenti

   Apache
   http://www.apache.org/dist/httpd/Announcement2.4.html
   http://httpd.apache.org/security/vulnerabilities_24.html

   Mitre's CVE ID
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4352
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0117
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0118
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0226
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0231
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3523

   Ubuntu Security Notice
   http://www.ubuntu.com/usn/usn-2299-1/

   Red Hat Security Advisory
   https://rhn.redhat.com/errata/RHSA-2014-0920.html
   https://rhn.redhat.com/errata/RHSA-2014-0921.html
   https://rhn.redhat.com/errata/RHSA-2014-0922.html


GARR CERT Newsletter subscribe/unsubscribe:
http://www.cert.garr.it/alert/ricevi-gli-alert-di-cert

-----BEGIN PGP SIGNATURE-----

iD8DBQFT0h1dwZxMk2USYEIRApB1AKCKYSkEKeCmTLWqROayij6LKJmTDACcCcfU
uf6nMX534RaLMnvK1+7uU90=
=IyK5
-----END PGP SIGNATURE-----

 

Alert di GARR-CERT Usata per la segnalazione di allarmi di sicurezza e comunicazioni di interesse generale diretti agli enti GARR. L'iscrizione è aperta e consigliata a tutti, il posting è riservato ai membri di GARR-CERT