what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2012-019

Mandriva Linux Security Advisory 2012-019
Posted Feb 15, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-019 - tables/apr_hash.c in the Apache Portable Runtime library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service via crafted input to an application that maintains a hash table. APR has been upgraded to the latest version which holds many improvements over the previous versions and is not vulnerable to this issue.

tags | advisory, denial of service
systems | linux, mandriva
advisories | CVE-2012-0840
SHA-256 | 2f0732428057c2cf4982c39b6f22639ab7af589665b4b7b9078e4a48132c865e

Mandriva Linux Security Advisory 2012-019

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2012:019
http://www.mandriva.com/security/
_______________________________________________________________________

Package : apr
Date : February 14, 2012
Affected: 2010.1, 2011., Enterprise Server 5.0
_______________________________________________________________________

Problem Description:

A vulnerability has been found and corrected in ASF APR:

tables/apr_hash.c in the Apache Portable Runtime (APR) library through
1.4.5 computes hash values without restricting the ability to trigger
hash collisions predictably, which allows context-dependent attackers
to cause a denial of service (CPU consumption) via crafted input to
an application that maintains a hash table (CVE-2012-0840).

APR has been upgraded to the latest version (1.4.6) which holds
many improvments over the previous versions and is not vulnerable to
this issue.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0840
http://www.apache.org/dist/apr/CHANGES-APR-1.4
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2010.1:
1de7664f663207ff2e2b66ed38059f04 2010.1/i586/libapr1-1.4.6-0.1mdv2010.2.i586.rpm
f371aea1ad44fcdbc45d63c759ef7fb0 2010.1/i586/libapr-devel-1.4.6-0.1mdv2010.2.i586.rpm
698b79ec7009e77ba8d7d53b71434950 2010.1/SRPMS/apr-1.4.6-0.1mdv2010.2.src.rpm

Mandriva Linux 2010.1/X86_64:
d3f53d0a19a448ffc48bb000278e0284 2010.1/x86_64/lib64apr1-1.4.6-0.1mdv2010.2.x86_64.rpm
04118f9682910695ba84d82a32c98c32 2010.1/x86_64/lib64apr-devel-1.4.6-0.1mdv2010.2.x86_64.rpm
698b79ec7009e77ba8d7d53b71434950 2010.1/SRPMS/apr-1.4.6-0.1mdv2010.2.src.rpm

Mandriva Linux 2011:
1a06fc6721c20f950a04dc067344bbe4 2011/i586/libapr1-1.4.6-0.1-mdv2011.0.i586.rpm
ba7aaaaadf1e8336afb4c43b03cb9054 2011/i586/libapr-devel-1.4.6-0.1-mdv2011.0.i586.rpm
408e2ed975392cc47e9c0e6dce697d12 2011/SRPMS/apr-1.4.6-0.1.src.rpm

Mandriva Linux 2011/X86_64:
9d4e2c286abf5a227512c75b3f0ccb18 2011/x86_64/lib64apr1-1.4.6-0.1-mdv2011.0.x86_64.rpm
05a9e3242ea9058d591849c035960c55 2011/x86_64/lib64apr-devel-1.4.6-0.1-mdv2011.0.x86_64.rpm
408e2ed975392cc47e9c0e6dce697d12 2011/SRPMS/apr-1.4.6-0.1.src.rpm

Mandriva Enterprise Server 5:
173d17df305532e677eacb61427fc290 mes5/i586/libapr1-1.4.6-0.1mdvmes5.2.i586.rpm
cd21d21a2fef2b9cc5b5f13c3bb78e74 mes5/i586/libapr-devel-1.4.6-0.1mdvmes5.2.i586.rpm
9eb866bcc8c407845edf67c6be078bcc mes5/SRPMS/apr-1.4.6-0.1mdvmes5.2.src.rpm

Mandriva Enterprise Server 5/X86_64:
029327d54965590a23af96af702af87a mes5/x86_64/lib64apr1-1.4.6-0.1mdvmes5.2.x86_64.rpm
c8f4a0942de90fef566282be2272b0e3 mes5/x86_64/lib64apr-devel-1.4.6-0.1mdvmes5.2.x86_64.rpm
9eb866bcc8c407845edf67c6be078bcc mes5/SRPMS/apr-1.4.6-0.1mdvmes5.2.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iD8DBQFPOja+mqjQ0CJFipgRAp9EAJ4qEv7J7UE2wjx5qker0jmSjb1w0QCfd5ww
8aKnTFrwxpgClJVD3/1GqCI=
=EGzk
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close