Ubuntu Security Notice USN-3373-1

Discussion in 'News Aggregator' started by Packet Storm, 1 Aug 2017.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3373-1 - Emmanuel Dreyfus discovered that third-party modules using the ap_get_basic_auth_pw function outside of the authentication phase may lead to authentication requirements being bypassed. This update adds a new ap_get_basic_auth_components function for use by third-party modules. Vasileios Panopoulos discovered that the Apache mod_ssl module may crash when third-party modules call ap_hook_process_connection during an HTTP request to an HTTPS port. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...