Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Apache Server Side Include Cross Site Scripting Vulnerability

Solution:
Oracle has stated that fixes for affected software will be available through metalink. A release schedule for these fixes has been made available.

HP has released a security bulletin. Customers of HP-UX are advised to download Apache 1.3.27.00 and 2.0.43.00 product bundles from:

http://www.software.hp.com/ISS_products_list.html

HP has advised NNM (Network Node Manager) customers to refrain from installing these product bundles. Further details are available in the referenced advisory.

Debian has released advisory DSA 195-1, which contains updates for apache-perl packages. Further information is available in the referenced advisory.

Gentoo Linux has released an advisory. Users of net-www/apache-2.0.42 and earlier are urged to update their systems by issuing the following commands:

emerge rsync
emerge apache
emerge clean

RedHat has released a security advisory (RHSA-2002:222-21) which contains fixes that address this issue. Further details can be obtained from the referenced advisory.

SGI has released an upaded advisory which contains fix information. Users are advised to install sgi_apache v1.3.27a distribution from the IRIX 6.5.20
Applications CD or download it. Please see the referenced advisory for further information about obtaining and applying fixes.

SCO has released an advisory (CSSA-2003-SCO.10.1) to address this issue for OpenServer. Please see the attached advisory for details on obtaining and applying fixes.

This issue has been addressed in Apache versions 1.3.27 and 2.0.43.


Sun Cobalt RaQ 4

Sun Cobalt RaQ XTR

Sun Cobalt RaQ 550

Sun Cobalt Qube 3

Apache Software Foundation Apache 1.3.19

Apache Software Foundation Apache 1.3.20

Apache Software Foundation Apache 1.3.22

Apache Software Foundation Apache 1.3.23

Apache Software Foundation Apache 1.3.24

Apache Software Foundation Apache 1.3.25

Apache Software Foundation Apache 1.3.26

Apache Software Foundation Apache 1.3.9

HP HP-UX 11.0

HP HP-UX 11.11

HP HP-UX 11.20

HP HP-UX 11.22

Apache Software Foundation Apache 2.0

Apache Software Foundation Apache 2.0.28

Apache Software Foundation Apache 2.0.32

Apache Software Foundation Apache 2.0.35

Apache Software Foundation Apache 2.0.36

Apache Software Foundation Apache 2.0.37

Apache Software Foundation Apache 2.0.38

Apache Software Foundation Apache 2.0.39

Apache Software Foundation Apache 2.0.40

Apache Software Foundation Apache 2.0.41

Apache Software Foundation Apache 2.0.42

HP VirtualVault 4.5

HP VirtualVault 4.6

HP OpenView Network Node Manager 6.2 Solaris

HP OpenView Network Node Manager 6.2 HP-UX 11.X

HP OpenView Network Node Manager 6.2 HP-UX 10.X







 

Privacy Statement
Copyright 2008, SecurityFocus