Apache Web Server文件描述符泄露漏洞发布时间:2003-04-02 更新时间:2003-04-09 严重程度:中 威胁程度:服务器信息泄露 错误类型:意外情况处置错误 利用方式:服务器模式 BUGTRAQ ID:7255 受影响系统 Apache Software Foundation Apache 2.0.39详细描述 Apache服务程序对文件描述符处理存在问题,可导致泄露敏感信息。 漏洞是因为子进程不正确继承文件描述符所致,可导致攻击者访问敏感日志信息。 测试代码 尚无 解决方案 升级程序: Apache Software Foundation Apache 2.0.39: Apache Software Foundation Upgrade Apache httpd 2.0.45 http://www.apache.org/dist/httpd/ Apache Software Foundation Apache 2.0.40: Apache Software Foundation Upgrade Apache httpd 2.0.45 http://www.apache.org/dist/httpd/ Red Hat Upgrade httpd-2.0.40-11.3.i386.rpm ftp://updates.redhat.com/8.0/en/os/i386/httpd-2.0.40-11.3.i386.rpm Red Hat Upgrade httpd-2.0.40-21.1.i386.rpm ftp://updates.redhat.com/9/en/os/i386/httpd-2.0.40-21.1.i386.rpm Red Hat Upgrade httpd-devel-2.0.40-11.3.i386.rpm ftp://updates.redhat.com/8.0/en/os/i386/httpd-devel-2.0.40-11.3.i386.rpm Red Hat Upgrade httpd-devel-2.0.40-21.1.i386.rpm ftp://updates.redhat.com/9/en/os/i386/httpd-devel-2.0.40-21.1.i386.rpm Red Hat Upgrade httpd-manual-2.0.40-11.3.i386.rpm ftp://updates.redhat.com/8.0/en/os/i386/httpd-manual-2.0.40-11.3.i386.rpm Red Hat Upgrade httpd-manual-2.0.40-21.1.i386.rpm ftp://updates.redhat.com/9/en/os/i386/httpd-manual-2.0.40-21.1.i386.rpm Red Hat Upgrade mod_ssl-2.0.40-11.3.i386.rpm ftp://updates.redhat.com/8.0/en/os/i386/mod_ssl-2.0.40-11.3.i386.rpm Red Hat Upgrade mod_ssl-2.0.40-21.1.i386.rpm ftp://updates.redhat.com/9/en/os/i386/mod_ssl-2.0.40-21.1.i386.rpm Apache Software Foundation Apache 2.0.41: Apache Software Foundation Upgrade Apache httpd 2.0.45 http://www.apache.org/dist/httpd/ Apache Software Foundation Apache 2.0.42: Apache Software Foundation Upgrade Apache httpd 2.0.45 http://www.apache.org/dist/httpd/ Apache Software Foundation Apache 2.0.43: Apache Software Foundation Upgrade Apache httpd 2.0.45 http://www.apache.org/dist/httpd/ Apache Software Foundation Apache 2.0.44: Apache Software Foundation Upgrade Apache httpd 2.0.45 http://www.apache.org/dist/httpd/ 相关信息 Christian Kratzer <ck@cksoft.de>, Bjoern A. Zeeb <bz@zabbadoz.net>. 参考:http://www.securityfocus.com/advisories/5266 http://www.apache.org/dist/httpd/Announcement2.html http://www.apache.org/dist/httpd/CHANGES_2.0 |