apr-1.3.9-3.2.0.2.AXS4

エラータID: AXSA:2011-669:02

リリース日: 
2011/12/28 Wednesday - 14:37
題名: 
apr-1.3.9-3.2.0.2.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

The mission of the Apache Portable Runtime (APR) is to provide a free library of C data structures and routines, forming a system portability layer to as many operating systems as possible, including Unices, MS Win32, BeOS and OS/2.
Security issues fixed with this release:
CVE-2011-1928
The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used. NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.

解決策: 

Update packages.

追加情報: 

From Asianux Server 4 SP1.

ダウンロード: 

SRPMS
  1. apr-1.3.9-3.2.0.2.AXS4.src.rpm
    MD5: f57a7713d4508fc0e346dff219d6bc02
    SHA-256: e6e85eff41e67c9541e325cf07335427cdc05e6e6cf4df698677e431e8ba9995
    Size: 934.85 kB

Asianux Server 4 for x86
  1. apr-1.3.9-3.2.0.2.AXS4.i686.rpm
    MD5: 671b944af37accc6346c0c7952c85cf6
    SHA-256: db9a5fd658a274f65303f7dfdd247cb98a28814fab5234bd25bcea6dcf621ce4
    Size: 128.30 kB
  2. apr-devel-1.3.9-3.2.0.2.AXS4.i686.rpm
    MD5: 555613c4598caaba60255e140f8caac5
    SHA-256: c963fa08436128f5d3a90c966b8d08437aab534f80e6a5529fee7f5e1ed149b3
    Size: 175.86 kB

Asianux Server 4 for x86_64
  1. apr-1.3.9-3.2.0.2.AXS4.x86_64.rpm
    MD5: 36effd4a08433fcfa297942b014181df
    SHA-256: 3c1db45fcfe7aabf86f9df5b585c5417d41cf1b4393f03cad7c2e191a8b98734
    Size: 122.18 kB
  2. apr-devel-1.3.9-3.2.0.2.AXS4.x86_64.rpm
    MD5: 8350e65a43ad0f80473aba8d5c5fa433
    SHA-256: e7d0df2eb881f28b710828687da811dbc66e292495246f74b8fe7dec9e32e5be
    Size: 175.44 kB
  3. apr-1.3.9-3.2.0.2.AXS4.i686.rpm
    MD5: 671b944af37accc6346c0c7952c85cf6
    SHA-256: db9a5fd658a274f65303f7dfdd247cb98a28814fab5234bd25bcea6dcf621ce4
    Size: 128.30 kB
  4. apr-devel-1.3.9-3.2.0.2.AXS4.i686.rpm
    MD5: 555613c4598caaba60255e140f8caac5
    SHA-256: c963fa08436128f5d3a90c966b8d08437aab534f80e6a5529fee7f5e1ed149b3
    Size: 175.86 kB