Description: Red Hat has issued updates for httpd. These fix vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and by malicious people to conduct cross-site scripting attacks.
1) An error in the mod_status module can be exploited by malicious people to conduct cross-site scripting attacks.
3) An error in the mod_cache module in the handling of Cache-Control headers can be exploited to crash the child process via specially crafted requests. This could lead to a DoS if using a threaded Multi-Processing Module.
Solution: Updated packages are available from Red Hat Network. http://rhn.redhat.com
Changelog: 2007-07-13: Red Hat released updated packages for Red Hat Enterprise Linux AS, WS, and ES version 3 and 4.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.