Important: httpd (SL4, SL5, SL6)

Synopsis: Important: httpd security update
Issue Date: 2011-08-31
CVE Numbers: CVE-2011-3192

The Apache HTTP Server is a popular web server.

A flaw was found in the way the Apache HTTP Server handled Range HTTP
headers. A remote attacker could use this flaw to cause httpd to use an
excessive amount of memory and CPU time via HTTP requests with a
specially-crafted Range header. (CVE-2011-3192)

All httpd users should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.

SL4
x86_64
httpd-2.0.52-48.ent.x86_64.rpm
httpd-devel-2.0.52-48.ent.x86_64.rpm
httpd-manual-2.0.52-48.ent.x86_64.rpm
httpd-suexec-2.0.52-48.ent.x86_64.rpm
mod_ssl-2.0.52-48.ent.x86_64.rpm
i386
httpd-2.0.52-48.ent.i386.rpm
httpd-devel-2.0.52-48.ent.i386.rpm
httpd-manual-2.0.52-48.ent.i386.rpm
httpd-suexec-2.0.52-48.ent.i386.rpm
mod_ssl-2.0.52-48.ent.i386.rpm
SL5
x86_64
httpd-2.2.3-53.el5_7.1.x86_64.rpm
httpd-devel-2.2.3-53.el5_7.1.i386.rpm
httpd-devel-2.2.3-53.el5_7.1.x86_64.rpm
httpd-manual-2.2.3-53.el5_7.1.x86_64.rpm
mod_ssl-2.2.3-53.el5_7.1.x86_64.rpm
i386
httpd-2.2.3-53.el5_7.1.i386.rpm
httpd-devel-2.2.3-53.el5_7.1.i386.rpm
httpd-manual-2.2.3-53.el5_7.1.i386.rpm
mod_ssl-2.2.3-53.el5_7.1.i386.rpm
SL6
x86_64
httpd-2.2.15-9.el6_1.2.x86_64.rpm
httpd-devel-2.2.15-9.el6_1.2.i686.rpm
httpd-devel-2.2.15-9.el6_1.2.x86_64.rpm
httpd-tools-2.2.15-9.el6_1.2.x86_64.rpm
mod_ssl-2.2.15-9.el6_1.2.x86_64.rpm
i386
httpd-2.2.15-9.el6_1.2.i686.rpm
httpd-devel-2.2.15-9.el6_1.2.i686.rpm
httpd-tools-2.2.15-9.el6_1.2.i686.rpm
mod_ssl-2.2.15-9.el6_1.2.i686.rpm
noarch
httpd-manual-2.2.15-9.el6_1.2.noarch.rpm

– Scientific Linux Development Team