Wind River Support Network

HomeOther DownloadsSecurity Advisory - appache http server 2.0 - CVE-2007-6388
Recommended Type: Patch

Security Advisory - appache http server 2.0 - CVE-2007-6388

Released: Jul 8, 2008     Updated: Jul 8, 2008

Description

Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6388 IDENTIFIER = WIND00118351


Product Version

Linux Platforms 2.0, Linux Platforms 1.x

Downloads


Installation Notes

Installation Notes

WIND00123015.zip is for 2.0
WIND00123017.zip is for 1.4
WIND00123018.zip is for 1.5

1. Unzip the patch under [install_dir]/updates

2. Install the patch CD by entering the patch CD directory and run setup_linux.

3. This is a source only patch so you will have to build the kernel

4. Issue a make fs and make the kernel in a configured directory.

5. Upload the kernel and rootfs into the target and boot it up.


Live chat
Online