SB2011101705 - Resource management error in apache2 (Alpine package)
Published: October 17, 2011
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2011-3348)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
Remediation
Install update from vendor's website.