Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Servers & Networking
FedoraForum Search

Forgot Password? Join Us!

Servers & Networking Discuss any Fedora server problems and Networking issues such as dhcp, IP numbers, wlan, modems, etc.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 12th March 2010, 09:11 PM
ravigpalli Offline
Registered User
 
Join Date: Mar 2010
Posts: 6
windows_xp_2003ie
Apache 2.2.11 Vulnarabilities....Solution Required

Hi,

I am using Nagios 3.2.4 tool with Nagios-Plugins-1.4.14 and on Red Hat Fedora Linux ver 10.1.The Apache version is 2.2.11

My security team has identified the following vulnerabilities with this version and they want me to find a fix.

1)Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of
Service Vulnerability

2)Apache HTTP Server mod_proxy stream_reqbody_cl Function Denial of Service Vulnerability

3)Apache HTTP Server mod_deflate Remote Denial Of Service Vulnerability

4)Apache APR and APR-util Multiple Integer Overflow Vulnerabilities

Please some one help me how can I fix these vulnarabilities.

Thanks a lot in advance.

Regards,
Ravi G
Reply With Quote
  #2  
Old 13th March 2010, 04:13 AM
madhavdiwan Offline
Registered User
 
Join Date: Jun 2009
Posts: 472
windows_xp_2003firefox
Re: Apache 2.2.11 Vulnarabilities....Solution Required

Ravi ,
you have several options.

1) if you are NOT using the modules , and they are simply loaded because they came with Apache. , disable and unload them via commenting them out in the Apache config file and reloading Apache

2) if you absolutely DO need them , consider upgrading the server , Apache, or even just the modules.

I suggest you go to apache.org and find out what each module is meant to do, and then find out if you need the module for your particular websites.

next make sure that the Apache version and apache addon packages for your version of Fedora , are the latest for that Fedora version. and verify in which version the issues are fixed .. so that you know what minimum patches or versions you need to fulfil your security team's requirements.

If you can not upgrade , due to some legacy issue / old software requirements, etc.. there are still some things you can do to alleviate the risks , which should satisfy any security team, for instance:

If this server serves a production website , you should also seriously consider putting a reverse web proxy in front of it ( a squid server would work well ) so that the connections to the apache web server first get filtered and policed by the proxy server before any connection the the actual web server is made.
Reply With Quote
  #3  
Old 13th March 2010, 04:18 AM
Dan's Avatar
Dan Offline
Administrator
 
Join Date: Jun 2006
Location: Paris, TX
Posts: 22,309
linuxfedorafirefox
Re: Apache 2.2.11 Vulnarabilities....Solution Required

(Moved to servers)
__________________
Signature Links | New Posts | Who's on the forums (right now) |

© ® ™ № ¿
Reply With Quote
  #4  
Old 13th March 2010, 07:27 PM
madhavdiwan Offline
Registered User
 
Join Date: Jun 2009
Posts: 472
windows_xp_2003firefox
Re: Apache 2.2.11 Vulnarabilities....Solution Required

Quote:
Red Hat Fedora Linux ver 10.1.
Do you mean you are running Fedora 10 ?
Reply With Quote
  #5  
Old 15th March 2010, 05:05 PM
ravigpalli Offline
Registered User
 
Join Date: Mar 2010
Posts: 6
windows_xp_2003ie
Re: Apache 2.2.11 Vulnarabilities....Solution Required

Yes I am running Fedora 10....

Please some one provide solution...

Thanks,
Ravi
Reply With Quote
  #6  
Old 15th March 2010, 07:07 PM
pete_1967 Online
Clueless in a Cuckooland
 
Join Date: Mar 2006
Location: Here now, elsewhere tomorrow.
Posts: 3,916
linuxfedorafirefox
Re: Apache 2.2.11 Vulnarabilities....Solution Required

madhavdiwan gave you two, third is: apply the patches you want yourself, it's not rocket science.
__________________
A Drink is Not Just For Christmas - SaskyCom :thumb:


“Give a man a fish; you have fed him for today. Teach a man to fish; and you have fed him for a lifetime” so now go and...
RTFM FIRST: http://docs.fedoraproject.org/ & http://rute.2038bug.com/index.html.gz
Reply With Quote
  #7  
Old 18th March 2010, 11:08 PM
bodhi.zazen's Avatar
bodhi.zazen Offline
Registered User
 
Join Date: Jul 2006
Location: Montana
Posts: 731
windows_xp_2003firefox
Re: Apache 2.2.11 Vulnarabilities....Solution Required

Quote:
Originally Posted by ravigpalli View Post
Yes I am running Fedora 10....

Please some one provide solution...

Thanks,
Ravi
You google those alerts and the solutions.

Fro example :

mod_proxy_ftp Module NULL Pointer Dereference Denial Of
Service Vulnerability

http://www.securityfocus.com/bid/36260/references

In general the solution is to update either apache or the module in questions. If a rpm for fedora 10 is available , you can use that.

If there is no rpm available, well in that case I personally would start compiling, but installing the development packages on a production server has it's own set of vulnerabilities - to that means building on a separate installation.

If you have dependency problems, you will need to resolve them , which may or may not involve installing a new OS.

You other solutions are to simply disable those modules or look at additional modules such as mod_evasive and / or mod_security. Mod_security may well take some time and effort to configure, depending on what your are running on Apache .

Last, why are you running Fedora 10 as a server ? Personally I would look at Centos or RHEL.

F10 is beyond EOL :

http://fedoraproject.org/wiki/LifeCycle/EOL

meaning no more updates for you.

With that information in mind, I again suggest you update your OS and, if it were me, I would look at RHEL or Centos rather then Fedora.
__________________
If it is not broken, tweak it... If you break Fedora you get to keep both pieces :p
Reply With Quote
Reply

Tags
apache, required, vulnarabilitiessolution

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help Required - X not starting BlownCPU Using Fedora 6 26th January 2009 05:55 PM
Apache mod_authnz_ldap Segfault - SOLUTION jgarrison Using Fedora 1 21st January 2009 08:43 PM
Lib required notfound Using Fedora 5 6th September 2007 01:42 PM


Current GMT-time: 04:06 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat