[Bug 839390] Re: Apache+Kerberos not working anymore since update today
Dave Walker
davewalker at ubuntu.com
Tue Sep 20 23:11:25 UTC 2011
It is currently believed that this was introduced by?
apache2 (2.2.14-5ubuntu8.6) lucid-security; urgency=low
* SECURITY UPDATE: Range header DoS vulnerability
- debian/patches/207_CVE-2011-3192.dpatch: filter out large
byte ranges and improve memory efficiency in handling buckets.
(thanks to Debian and upstream)
- CVE-2011-3192
* Include fix for regressions introduced by above patch:
- debian/patches/208_CVE-2011-3192_regression.dpatch: return 206
and 416 response codes where appropriate (see deban bug 639825)
-- Steve Beattie <sbeattie at ubuntu.com (sbeattie: 3910) > Thu, 01 Sep 2011 01:52:17 -0700
** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2011-3192
** Changed in: apache2 (Ubuntu)
Status: New => Incomplete
--
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to apache2 in Ubuntu.
https://bugs.launchpad.net/bugs/839390
Title:
Apache+Kerberos not working anymore since update today
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/839390/+subscriptions
More information about the Ubuntu-server-bugs
mailing list