Gentoo Linux Advisories: apache, tomcat | Linux Today

Gentoo Linux Advisories: apache, tomcat

Written By
Web Webster
Web Webster
Oct 15, 2002
- - --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200210-002
- - --------------------------------------------------------------------

PACKAGE : apache
SUMMARY : shared memory scoreboard vulnerabilities
EXPLOIT : local
DATE    : 2002-10-15 08:25 UTC

- - --------------------------------------------------------------------

Apache HTTP Server contains a vulnerability in its shared memory 
scoreboard. Attackers who can execute commands under the Apache
UID can either send a (SIGUSR1) signal to any process as root, in 
most cases killing the process, or launch a local denial of service (DoS)
attack.

Read the full advisory at
http://www.idefense.com/advisory/10.03.02.txt

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-www/apache-1.3.26-r4 and earlier update their systems
as follows:

emerge rsync
emerge apache
emerge clean

- - --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
- - --------------------------------------------------------------------

- - --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200210-001
- - --------------------------------------------------------------------

PACKAGE : tomcat
SUMMARY : source disclosure
EXPLOIT : remote
DATE    : 2002-10-15 08:15 UTC

- - --------------------------------------------------------------------

A security vulnerability has been confirmed to exist in Apache Tomcat
4.0.x releases (including Tomcat 4.0.5), which allows to use a specially
crafted URL to return the unprocessed source of a JSP page, or, under
special circumstances, a static resource which would otherwise have been
protected by security constraint, without the need for being properly
authenticated. This is based on a variant of the exploit that was
disclosed on 09/24/2002.

Read the full disclosure at
http://marc.theaimsgroup.com/?l=tomcat-dev&m=103417249325526&w=2

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-www/tomcat-4.0.5 and earlier update their systems
as follows:

emerge rsync
emerge tomcat
emerge clean

- - --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz
- - --------------------------------------------------------------------

Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.