Prestashop 8.1.5
185 vulnérabilités ont été trouvés
3 paquets abandonnés ont été trouvés
Dernière analyse : il y a 2 heures
Vulnérabilités
Paquets concernés : 13
- Critique 14
- Haute 48
- Moyenne 87
- Basse 8
- Non classée 2
-
Composer
95
-
Apache/http_server
90
Composer
Vulnérabilités
- Critique 2
- Haute 26
- Moyenne 36
- Basse 5
- Non classée 0
-
Haute CVE-2025-31481 Signalée 04/04/2025GraphQL query operations security can be bypassed
- Versions affectées
<4.0.22- Versions patchées
4.0.224.0.22
-
Haute CVE-2025-31485 Signalée 04/04/2025GraphQL grant on a property might be cached with different objects
- Versions affectées
<4.0.22- Versions patchées
4.0.224.0.22
-
Moyenne CVE-2026-49858 Signalée 10/07/2026API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
- Versions affectées
>=4.3.0,<4.3.8|>=4.2.0,<4.2.25|>=2.6.0,<4.1.29- Versions patchées
4.1.294.2.254.3.84.1.294.2.254.3.84.1.294.2.254.3.8
-
Moyenne CVE-2026-54164 Signalée 07/08/2026API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
- Versions affectées
>=4.3.0,<4.3.12|>=4.2.0,<4.2.26|<4.1.30- Versions patchées
4.1.304.2.264.3.12
-
Haute CVE-2026-69246 Signalée 03/08/2026Guzzle: Noncanonical host can bypass host-based checks
- Versions affectées
>=8.0.0,<8.0.1|<7.15.2- Versions patchées
7.15.28.0.1
-
Moyenne CVE-2026-55767 Signalée 18/06/2026Dot-only cookie domains match all hosts
- Versions affectées
<7.12.1- Versions patchées
7.12.1
https://github.com/guzzle/guzzle/security/advisories/GHSA-cwxw-98qj-8qjx
-
Moyenne Signalée 20/07/2026Guzzle: Unbounded response cookies risk denial of service
- Versions affectées
<7.15.1- Versions patchées
7.15.1
-
Moyenne CVE-2026-59883 Signalée 20/07/2026Guzzle: Cookie Disclosure and Injection via IP-Address Domains
- Versions affectées
<7.12.3- Versions patchées
7.12.3
-
Moyenne CVE-2026-69245 Signalée 03/08/2026Guzzle: Noncanonical cookie domain keeps subdomain scope
- Versions affectées
>=8.0.0,<8.0.1|<7.15.2- Versions patchées
7.15.28.0.1
-
Moyenne Signalée 20/07/2026Guzzle: URI fragments disclosed in redirect Referer headers
- Versions affectées
<7.15.1- Versions patchées
7.15.1
-
Moyenne CVE-2026-55568 Signalée 18/06/2026Silent HTTPS proxy downgrade to cleartext
- Versions affectées
<7.12.1- Versions patchées
7.12.1
https://github.com/guzzle/guzzle/security/advisories/GHSA-wpwq-4j6v-78m3
-
Moyenne Signalée 20/07/2026Guzzle: Proxy-Authorization headers can be sent to origin servers
- Versions affectées
<7.14.2- Versions patchées
7.14.2
-
Moyenne Signalée 20/07/2026Guzzle: Host-only cookie scope is not preserved
- Versions affectées
<7.15.1- Versions patchées
7.15.1
-
Moyenne CVE-2026-55766 Signalée 18/06/2026CRLF injection in HTTP start-line serialization
- Versions affectées
<2.12.1- Versions patchées
2.12.1
https://github.com/guzzle/psr7/security/advisories/GHSA-vm85-hxw5-5432
-
Moyenne CVE-2026-49214 Signalée 11/06/2026guzzlehttp/psr7 has CRLF Injection via URI Host Component
- Versions affectées
<2.10.2- Versions patchées
2.10.2
-
Moyenne CVE-2026-48998 Signalée 11/06/2026guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
- Versions affectées
<2.10.2- Versions patchées
2.10.2
-
Moyenne CVE-2026-59882 Signalée 21/07/2026guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
- Versions affectées
<2.12.3- Versions patchées
2.12.3
-
Haute CVE-2023-37260 Signalée 06/07/2023league/oauth2-server key exposed in exception message when passing as a string and providing an invalid pass phrase
- Versions affectées
>=8.5.0,<8.5.3|>=8.3.2,<8.4.2- Versions patchées
8.4.28.5.3
-
Critique CVE-2026-45034 Signalée 08/06/2026PHPSpreadsheet has a patch bypass for CVE-2026-34084
- Versions affectées
<=1.30.4- Versions patchées
1.30.5
-
Haute CVE-2024-56366 Signalée 03/01/2025PhpSpreadsheet allows unauthorized Reflected XSS in the Accounting.php file
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Haute CVE-2025-54370 Signalée 25/08/2025PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser
- Versions affectées
>=4.0.0,<5.0.0|>=3.0.0,<3.10.0|>=2.2.0,<2.4.0|>=2.0.0,<2.1.12|<1.30.0- Versions patchées
1.30.02.1.122.4.03.10.05.0.0
-
Haute CVE-2026-34084 Signalée 29/04/2026PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled
- Versions affectées
<=1.30.2|>=2.0.0,<=2.1.14|>=2.2.0,<=2.4.3|>=3.3.0,<=3.10.3|>=4.0.0,<=5.5.0- Versions patchées
5.6.03.10.42.4.42.1.151.30.3
-
Haute CVE-2024-56408 Signalée 03/01/2025PhpSpreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Haute CVE-2024-47873 Signalée 18/11/2024XmlScanner bypass leads to XXE
- Versions affectées
>=3.3.0,<3.4.0|>=2.2.0,<2.3.2|>=2.0.0,<2.1.3|<1.29.4- Versions patchées
1.29.42.1.32.3.23.4.0
-
Haute CVE-2026-59931 Signalée 23/07/2026PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
- Versions affectées
<=1.30.5|>=2.0.0,<=2.1.17|>=2.2.0,<=2.4.6|>=3.3.0,<=3.10.6|>=4.0.0,<=5.8.0- Versions patchées
5.8.13.10.72.4.72.1.181.30.6
-
Haute CVE-2024-48917 Signalée 18/11/2024XXE in PHPSpreadsheet's XLSX reader
- Versions affectées
>=3.3.0,<3.4.0|>=2.2.0,<2.3.2|>=2.0.0,<2.1.3|<1.29.4- Versions patchées
1.29.42.1.32.3.23.4.0
-
Haute CVE-2026-40902 Signalée 29/04/2026PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
- Versions affectées
<=1.30.3|>=2.0.0,<=2.1.15|>=2.2.0,<=2.4.4|>=3.3.0,<=3.10.4|>=4.0.0,<=5.6.0- Versions patchées
5.7.03.10.52.4.52.1.161.30.4
-
Haute CVE-2024-56365 Signalée 03/01/2025PhpSpreadsheet allows unauthorized Reflected XSS in the constructor of the Downloader class
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Haute CVE-2026-59932 Signalée 23/07/2026PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
- Versions affectées
<=1.30.5|>=2.0.0,<=2.1.17|>=2.2.0,<=2.4.6|>=3.3.0,<=3.10.6|>=4.0.0,<=5.8.0- Versions patchées
5.8.13.10.72.4.72.1.181.30.6
-
Haute CVE-2024-45293 Signalée 07/10/2024XXE in PHPSpreadsheet's XLSX reader
- Versions affectées
>=2.0.0,<2.1.1|<1.29.1|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.12.1.1
-
Haute CVE-2026-59933 Signalée 23/07/2026PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
- Versions affectées
<=1.30.5|>=2.0.0,<=2.1.17|>=2.2.0,<=2.4.6|>=3.3.0,<=3.10.6|>=4.0.0,<=5.8.0- Versions patchées
5.8.13.10.72.4.72.1.181.30.6
-
Haute CVE-2026-40863 Signalée 29/04/2026PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
- Versions affectées
<=1.30.3|>=2.0.0,<=2.1.15|>=2.2.0,<=2.4.4|>=3.3.0,<=3.10.4|>=4.0.0,<=5.6.0- Versions patchées
5.7.03.10.52.4.52.1.161.30.4
-
Haute CVE-2024-45290 Signalée 07/10/2024PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery when opening XLSX file
- Versions affectées
>=2.0.0,<2.1.1|<1.29.2|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.22.1.1
-
Haute CVE-2024-45048 Signalée 29/08/2024XXE in PHPSpreadsheet encoding is returned
- Versions affectées
<2.2.1- Versions patchées
2.2.1
-
Haute CVE-2024-56409 Signalée 03/01/2025PhpSpreadsheet allows unauthorized Reflected XSS in Currency.php file
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Moyenne CVE-2024-56410 Signalée 03/01/2025PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability in custom properties
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Moyenne CVE-2024-45291 Signalée 07/10/2024PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled
- Versions affectées
>=2.0.0,<2.1.1|<1.29.2|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.22.1.1
-
Moyenne CVE-2024-56412 Signalée 03/01/2025PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Moyenne CVE-2025-23210 Signalée 03/02/2025PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters
- Versions affectées
>=2.0.0,<2.1.8|>=2.2.0,<2.3.7|<1.29.9|>=3.0.0,<3.9.0- Versions patchées
3.9.01.29.92.3.72.1.8
-
Moyenne CVE-2024-45060 Signalée 07/10/2024PhpSpreadsheet has an Unauthenticated Cross-Site-Scripting (XSS) in sample file
- Versions affectées
>=2.0.0,<2.1.1|<1.29.2|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.22.1.1
-
Moyenne CVE-2026-40296 Signalée 28/04/2026PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer
- Versions affectées
<=1.30.3|>=2.0.0,<=2.1.15|>=2.2.0,<=2.4.4|>=3.3.0,<=3.10.4|>=4.0.0,<=5.6.0- Versions patchées
5.7.03.10.52.4.52.1.161.30.4
-
Moyenne CVE-2026-35453 Signalée 28/04/2026PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer
- Versions affectées
<=1.30.3|>=2.0.0,<=2.1.15|>=2.2.0,<=2.4.4|>=3.3.0,<=3.10.4|>=4.0.0,<=5.6.0- Versions patchées
5.7.03.10.52.4.52.1.161.30.4
-
Moyenne CVE-2024-45046 Signalée 29/08/2024PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information
- Versions affectées
<2.1.0- Versions patchées
2.1.0
-
Moyenne CVE-2024-56411 Signalée 03/01/2025PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Moyenne CVE-2024-45292 Signalée 07/10/2024PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks
- Versions affectées
>=2.0.0,<2.1.1|<1.29.2|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.22.1.1
-
Moyenne CVE-2025-22131 Signalée 21/01/2025Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet
- Versions affectées
>=2.2.0,<2.3.6|>=2.0.0,<2.1.7|<1.29.8|>=3.0.0,<3.8.0- Versions patchées
3.8.01.29.82.1.72.3.6
-
Moyenne CVE-2025-24027 Signalée 22/01/2025ps_contactinfo has a potential XSS due to usage of the nofilter tag in template
- Versions affectées
<=3.3.2- Versions patchées
3.3.3
-
Critique CVE-2026-54159 Signalée 10/07/2026prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
- Versions affectées
>=3.0.0,<4.0.4- Versions patchées
4.0.4
-
Haute CVE-2024-35226 Signalée 29/05/2024Smarty vulnerable to PHP Code Injection by malicious attribute in extends-tag
- Versions affectées
>=3.0.0,<4.5.3|>=5.0.0,<5.1.1- Versions patchées
5.1.14.5.3
-
Moyenne CVE-2026-62993 Signalée 01/09/2026Smarty: SSRF via redirect bypass of trusted_uri using {fetch}
- Versions affectées
<4.5.7|>=5.0.0,<5.8.2- Versions patchées
5.8.24.5.7
-
Moyenne CVE-2026-62992 Signalée 07/08/2026Smarty: Symlink path traversal out of trusted directories
- Versions affectées
<4.5.7|>=5.0.0,<5.8.2- Versions patchées
5.8.24.5.7
-
Non classée CVE-2026-46644 Signalée 26/05/2026CVE-2026-46644: symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence
- Versions affectées
>=1.17.1,<1.38.1
-
Haute CVE-2024-51736 Signalée 05/11/2024CVE-2024-51736: Command execution hijack on Windows with Process class
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7- Versions patchées
5.4.466.4.147.1.75.4.466.4.147.1.7
-
Haute CVE-2025-64500 Signalée 12/11/2025CVE-2025-64500: Incorrect parsing of PATH_INFO can lead to limited authorization bypass
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.50|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.29|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.3.7- Versions patchées
5.4.506.4.297.3.75.4.506.4.297.3.7
-
Moyenne CVE-2026-24739 Signalée 28/01/2026Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
- Versions affectées
>=8.0,<8.0.5|>=7.4,<7.4.5|>=7.3,<7.3.11|>=6.4,<6.4.33|<5.4.51- Versions patchées
5.4.516.4.337.3.117.4.58.0.55.4.516.4.337.3.117.4.58.0.5
-
Moyenne CVE-2023-46734 Signalée 10/11/2023CVE-2023-46734: Potential XSS vulnerabilities in CodeExtension filters
- Versions affectées
>=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<4.0.0|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.51|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.31|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.3.8- Versions patchées
4.4.515.4.316.3.84.4.515.4.316.3.8
-
Non classée CVE-2026-45077 Signalée 20/05/2026CVE-2026-45077: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Basse CVE-2024-50343 Signalée 30/08/2024CVE-2024-50343: Incorrect response from Validator when input ends with ` `
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.43|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.11|>=7.0.0,<7.1.0|>=7.1.0,<7.1.4- Versions patchées
5.4.436.4.117.1.45.4.436.4.117.1.4
-
Non classée CVE-2026-45073 Signalée 20/05/2026CVE-2026-45073: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45304 Signalée 20/05/2026CVE-2026-45304: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45065 Signalée 20/05/2026CVE-2026-45065: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45068 Signalée 20/05/2026CVE-2026-45068: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45071 Signalée 20/05/2026CVE-2026-45071: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45305 Signalée 20/05/2026CVE-2026-45305: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-48784 Signalée 26/05/2026CVE-2026-48784: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.53|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13
-
Non classée CVE-2026-48489 Signalée 26/05/2026CVE-2026-48489: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.53|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13
-
Non classée CVE-2026-45070 Signalée 20/05/2026CVE-2026-45070: Email Header Injection via Non-Token Characters in Mime Parameter Names
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Basse CVE-2024-50345 Signalée 05/11/2024CVE-2024-50345: Open redirect via browser-sanitized URLs
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7- Versions patchées
5.4.466.4.147.1.75.4.466.4.147.1.7
-
Basse CVE-2024-50342 Signalée 05/11/2024CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient
- Versions affectées
>=4.3.0,<4.4.0|>=4.4.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7- Versions patchées
5.4.466.4.147.1.75.4.466.4.147.1.7
-
Non classée CVE-2026-45133 Signalée 20/05/2026CVE-2026-45133: YAML Parser Stack Exhaustion via Unbounded Recursion in Nested Blocks, Sequences, and Mappings
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45063 Signalée 20/05/2026CVE-2026-45063: Identity Spoofing via Unanchored DN Regex in X509Authenticator
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45067 Signalée 20/05/2026CVE-2026-45067: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Haute CVE-2024-56521 Signalée 27/12/2024TCPDF missing certificate validation
- Versions affectées
<6.8.0- Versions patchées
6.8.0
-
Moyenne CVE-2024-51058 Signalée 26/11/2024TCPDF Local File Inclusion vulnerability
- Versions affectées
<=6.7.5- Versions patchées
6.7.6
-
Moyenne CVE-2024-32489 Signalée 15/04/2024TCPDF Cross-site Scripting vulnerability
- Versions affectées
<6.7.4- Versions patchées
6.7.4
-
Moyenne CVE-2024-22640 Signalée 19/04/2024TCPDF vulnerable to Regular Expression Denial of Service
- Versions affectées
<=6.7.4
-
Moyenne CVE-2024-56519 Signalée 27/12/2024TCPDF lacks SVG sanitization
- Versions affectées
<6.8.0- Versions patchées
6.8.0
-
Moyenne CVE-2024-56522 Signalée 27/12/2024TCPDF has incorrect comparison
- Versions affectées
<6.8.0- Versions patchées
6.8.0
-
Moyenne CVE-2024-56527 Signalée 27/12/2024TCPDF missing character escape on error messages
- Versions affectées
<6.8.0- Versions patchées
6.8.0
-
Haute CVE-2024-45411 Signalée 09/09/2024Twig has a possible sandbox bypass
- Versions affectées
>=3.0.0,<3.14.0|>=2.0.0,<2.16.1|>=1.0.0,<1.44.8- Versions patchées
1.44.82.16.13.14.0
-
Haute CVE-2026-49981 Signalée 01/07/2026Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
- Versions affectées
<=3.26.0- Versions patchées
3.27.0
-
Non classée CVE-2026-48806 Signalée 27/05/2026Sandbox `__toString()` policy bypass via dynamic mapping keys
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
https://symfony.com/blog/cve-2026-48806-sandbox-tostring-policy-bypass-via-dynamic-mapping-keys
-
Basse CVE-2024-51755 Signalée 06/11/2024Unguarded calls to __isset() and to array-accesses when the sandbox is enabled
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.11.2|>=3.12.0,<3.14.1- Versions patchées
3.11.23.14.1
-
Non classée CVE-2026-46638 Signalée 20/05/2026`{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-47732 Signalée 20/05/2026Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-48808 Signalée 27/05/2026Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
-
Non classée CVE-2026-48805 Signalée 27/05/2026Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
-
Non classée CVE-2026-46633 Signalée 20/05/2026PHP code injection via `{% use %}` template name
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-46627 Signalée 20/05/2026Sandbox does not protect against resource exhaustion
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-46635 Signalée 20/05/2026Sandbox property allowlist bypass via the `column` filter (array_column on objects)
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-46628 Signalée 20/05/2026The `spaceless` filter implicitly marks its output as safe
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-47730 Signalée 20/05/2026XSS in profiler HtmlDumper via unescaped template and profile names
- Versions affectées
>=3.0.0,<3.26.0
-
Non classée CVE-2026-48807 Signalée 27/05/2026Sandbox `__toString()` policy bypass via `Traversable` in `join`/`replace` and `in`/`not in` operators
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
-
Non classée CVE-2026-46636 Signalée 27/05/2026Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
-
Basse CVE-2024-51754 Signalée 06/11/2024Unguarded calls to __toString() when nesting an object into an array
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.11.2|>=3.12.0,<3.14.1- Versions patchées
3.11.23.14.1
https://symfony.com/blog/unguarded-calls-to-__tostring-when-nesting-an-object-into-an-array
Apache/http_server
Vulnérabilités
- Critique 12
- Haute 22
- Moyenne 51
- Basse 3
- Non classée 2
-
Critique CVE-2017-3167 Signalée 20/06/2017In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
* [http://www.securityfocus.com/bid/99135](http://www.securityfocus.com/bid/99135)
* [http://www.securitytracker.com/id/1038711](http://www.securitytracker.com/id/1038711)
* [https://www.nomachine.com/SU08O00185](https://www.nomachine.com/SU08O00185)
* [http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html](http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html)
* [https://security.gentoo.org/glsa/201710-32](https://security.gentoo.org/glsa/201710-32)
* [http://www.debian.org/security/2017/dsa-3896](http://www.debian.org/security/2017/dsa-3896)
* [https://support.apple.com/HT208221](https://support.apple.com/HT208221)
* [https://access.redhat.com/errata/RHSA-2017:3195](https://access.redhat.com/errata/RHSA-2017:3195)
* [https://access.redhat.com/errata/RHSA-2017:3194](https://access.redhat.com/errata/RHSA-2017:3194)
* [https://access.redhat.com/errata/RHSA-2017:3193](https://access.redhat.com/errata/RHSA-2017:3193)
* [https://access.redhat.com/errata/RHSA-2017:3477](https://access.redhat.com/errata/RHSA-2017:3477)
* [https://access.redhat.com/errata/RHSA-2017:3476](https://access.redhat.com/errata/RHSA-2017:3476)
* [https://access.redhat.com/errata/RHSA-2017:3475](https://access.redhat.com/errata/RHSA-2017:3475)
* [https://access.redhat.com/errata/RHSA-2017:2483](https://access.redhat.com/errata/RHSA-2017:2483)
* [https://access.redhat.com/errata/RHSA-2017:2479](https://access.redhat.com/errata/RHSA-2017:2479)
* [https://access.redhat.com/errata/RHSA-2017:2478](https://access.redhat.com/errata/RHSA-2017:2478)
* [https://security.netapp.com/advisory/ntap-20180601-0002/](https://security.netapp.com/advisory/ntap-20180601-0002/)
* [https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03908en_us](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03908en_us)
* [https://www.tenable.com/security/tns-2019-09](https://www.tenable.com/security/tns-2019-09)
* [https://lists.apache.org/thread.html/8409e41a8f7dd9ded37141c38df001be930115428c3d64f70bbdb8b4%40%3Cdev.httpd.apache.org%3E](https://lists.apache.org/thread.html/8409e41a8f7dd9ded37141c38df001be930115428c3d64f70bbdb8b4%40%3Cdev.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Critique CVE-2017-7679 Signalée 20/06/2017In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
* [http://www.securityfocus.com/bid/99170](http://www.securityfocus.com/bid/99170)
* [http://www.securitytracker.com/id/1038711](http://www.securitytracker.com/id/1038711)
* [https://www.nomachine.com/SU08O00185](https://www.nomachine.com/SU08O00185)
* [http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html](http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html)
* [https://security.gentoo.org/glsa/201710-32](https://security.gentoo.org/glsa/201710-32)
* [http://www.debian.org/security/2017/dsa-3896](http://www.debian.org/security/2017/dsa-3896)
* [https://support.apple.com/HT208221](https://support.apple.com/HT208221)
* [https://access.redhat.com/errata/RHSA-2017:3195](https://access.redhat.com/errata/RHSA-2017:3195)
* [https://access.redhat.com/errata/RHSA-2017:3194](https://access.redhat.com/errata/RHSA-2017:3194)
* [https://access.redhat.com/errata/RHSA-2017:3193](https://access.redhat.com/errata/RHSA-2017:3193)
* [https://access.redhat.com/errata/RHSA-2017:3477](https://access.redhat.com/errata/RHSA-2017:3477)
* [https://access.redhat.com/errata/RHSA-2017:3476](https://access.redhat.com/errata/RHSA-2017:3476)
* [https://access.redhat.com/errata/RHSA-2017:3475](https://access.redhat.com/errata/RHSA-2017:3475)
* [https://access.redhat.com/errata/RHSA-2017:2483](https://access.redhat.com/errata/RHSA-2017:2483)
* [https://access.redhat.com/errata/RHSA-2017:2479](https://access.redhat.com/errata/RHSA-2017:2479)
* [https://access.redhat.com/errata/RHSA-2017:2478](https://access.redhat.com/errata/RHSA-2017:2478)
* [https://github.com/gottburgm/Exploits/tree/master/CVE-2017-7679](https://github.com/gottburgm/Exploits/tree/master/CVE-2017-7679)
* [https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03821en_us](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03821en_us)
* [https://security.netapp.com/advisory/ntap-20180601-0002/](https://security.netapp.com/advisory/ntap-20180601-0002/)
* [https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03908en_us](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03908en_us)
* [https://www.tenable.com/security/tns-2019-09](https://www.tenable.com/security/tns-2019-09)
* [https://lists.apache.org/thread.html/f4515e580dfb6eeca589a5cdebd4c4c709ce632b12924f343c3b7751%40%3Cdev.httpd.apache.org%3E](https://lists.apache.org/thread.html/f4515e580dfb6eeca589a5cdebd4c4c709ce632b12924f343c3b7751%40%3Cdev.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Critique CVE-2017-9788 Signalée 13/07/2017In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://httpd.apache.org/security/vulnerabilities_22.html](https://httpd.apache.org/security/vulnerabilities_22.html)
* [http://www.securitytracker.com/id/1038906](http://www.securitytracker.com/id/1038906)
* [http://www.securityfocus.com/bid/99569](http://www.securityfocus.com/bid/99569)
* [http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html](http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html)
* [https://security.gentoo.org/glsa/201710-32](https://security.gentoo.org/glsa/201710-32)
* [http://www.debian.org/security/2017/dsa-3913](http://www.debian.org/security/2017/dsa-3913)
* [https://security.netapp.com/advisory/ntap-20170911-0002/](https://security.netapp.com/advisory/ntap-20170911-0002/)
* [https://support.apple.com/HT208221](https://support.apple.com/HT208221)
* [https://access.redhat.com/errata/RHSA-2017:3240](https://access.redhat.com/errata/RHSA-2017:3240)
* [https://access.redhat.com/errata/RHSA-2017:3239](https://access.redhat.com/errata/RHSA-2017:3239)
* [https://access.redhat.com/errata/RHSA-2017:3195](https://access.redhat.com/errata/RHSA-2017:3195)
* [https://access.redhat.com/errata/RHSA-2017:3194](https://access.redhat.com/errata/RHSA-2017:3194)
* [https://access.redhat.com/errata/RHSA-2017:3193](https://access.redhat.com/errata/RHSA-2017:3193)
* [https://access.redhat.com/errata/RHSA-2017:3114](https://access.redhat.com/errata/RHSA-2017:3114)
* [https://access.redhat.com/errata/RHSA-2017:3113](https://access.redhat.com/errata/RHSA-2017:3113)
* [https://access.redhat.com/errata/RHSA-2017:2710](https://access.redhat.com/errata/RHSA-2017:2710)
* [https://access.redhat.com/errata/RHSA-2017:2709](https://access.redhat.com/errata/RHSA-2017:2709)
* [https://access.redhat.com/errata/RHSA-2017:2708](https://access.redhat.com/errata/RHSA-2017:2708)
* [https://access.redhat.com/errata/RHSA-2017:2483](https://access.redhat.com/errata/RHSA-2017:2483)
* [https://access.redhat.com/errata/RHSA-2017:2479](https://access.redhat.com/errata/RHSA-2017:2479)
* [https://access.redhat.com/errata/RHSA-2017:2478](https://access.redhat.com/errata/RHSA-2017:2478)
* [https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03908en_us](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03908en_us)
* [https://www.tenable.com/security/tns-2019-09](https://www.tenable.com/security/tns-2019-09)
* [https://lists.apache.org/thread.html/0dd69204a6bd643cc4e9ccd008f07a9375525d977c6ebeb07a881afb%40%3Cannounce.httpd.apache.org%3E](https://lists.apache.org/thread.html/0dd69204a6bd643cc4e9ccd008f07a9375525d977c6ebeb07a881afb%40%3Cannounce.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Critique CVE-2021-39275 Signalée 16/09/2021ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html](https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html)
* [https://security.netapp.com/advisory/ntap-20211008-0004/](https://security.netapp.com/advisory/ntap-20211008-0004/)
* [https://www.debian.org/security/2021/dsa-4982](https://www.debian.org/security/2021/dsa-4982)
* [https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ)
* [https://www.oracle.com/security-alerts/cpujan2022.html](https://www.oracle.com/security-alerts/cpujan2022.html)
* [https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html)
* [https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/)
* [https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/) -
Critique CVE-2021-40438 Signalée 16/09/2021A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html](https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html)
* [https://security.netapp.com/advisory/ntap-20211008-0004/](https://security.netapp.com/advisory/ntap-20211008-0004/)
* [https://www.debian.org/security/2021/dsa-4982](https://www.debian.org/security/2021/dsa-4982)
* [https://www.tenable.com/security/tns-2021-17](https://www.tenable.com/security/tns-2021-17)
* [https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ)
* [https://www.oracle.com/security-alerts/cpujan2022.html](https://www.oracle.com/security-alerts/cpujan2022.html)
* [https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html)
* [https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/)
* [https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/)
* [https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E) -
Critique CVE-2021-44790 Signalée 20/12/2021A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
* [http://httpd.apache.org/security/vulnerabilities_24.html](http://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.openwall.com/lists/oss-security/2021/12/20/4](http://www.openwall.com/lists/oss-security/2021/12/20/4)
* [https://security.netapp.com/advisory/ntap-20211224-0001/](https://security.netapp.com/advisory/ntap-20211224-0001/)
* [https://www.debian.org/security/2022/dsa-5035](https://www.debian.org/security/2022/dsa-5035)
* [https://www.tenable.com/security/tns-2022-01](https://www.tenable.com/security/tns-2022-01)
* [https://www.tenable.com/security/tns-2022-03](https://www.tenable.com/security/tns-2022-03)
* [https://www.oracle.com/security-alerts/cpujan2022.html](https://www.oracle.com/security-alerts/cpujan2022.html)
* [https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html)
* [https://support.apple.com/kb/HT213255](https://support.apple.com/kb/HT213255)
* [https://support.apple.com/kb/HT213256](https://support.apple.com/kb/HT213256)
* [https://support.apple.com/kb/HT213257](https://support.apple.com/kb/HT213257)
* [http://seclists.org/fulldisclosure/2022/May/38](http://seclists.org/fulldisclosure/2022/May/38)
* [http://seclists.org/fulldisclosure/2022/May/33](http://seclists.org/fulldisclosure/2022/May/33)
* [http://seclists.org/fulldisclosure/2022/May/35](http://seclists.org/fulldisclosure/2022/May/35)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [http://packetstormsecurity.com/files/171631/Apache-2.4.x-Buffer-Overflow.html](http://packetstormsecurity.com/files/171631/Apache-2.4.x-Buffer-Overflow.html)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/) -
Critique CVE-2022-22720 Signalée 14/03/2022Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.openwall.com/lists/oss-security/2022/03/14/3](http://www.openwall.com/lists/oss-security/2022/03/14/3)
* [https://security.netapp.com/advisory/ntap-20220321-0001/](https://security.netapp.com/advisory/ntap-20220321-0001/)
* [https://lists.debian.org/debian-lts-announce/2022/03/msg00033.html](https://lists.debian.org/debian-lts-announce/2022/03/msg00033.html)
* [https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html)
* [https://support.apple.com/kb/HT213256](https://support.apple.com/kb/HT213256)
* [https://support.apple.com/kb/HT213257](https://support.apple.com/kb/HT213257)
* [https://support.apple.com/kb/HT213255](https://support.apple.com/kb/HT213255)
* [http://seclists.org/fulldisclosure/2022/May/38](http://seclists.org/fulldisclosure/2022/May/38)
* [http://seclists.org/fulldisclosure/2022/May/33](http://seclists.org/fulldisclosure/2022/May/33)
* [http://seclists.org/fulldisclosure/2022/May/35](http://seclists.org/fulldisclosure/2022/May/35)
* [https://www.oracle.com/security-alerts/cpujul2022.html](https://www.oracle.com/security-alerts/cpujul2022.html)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/) -
Critique CVE-2022-22721 Signalée 14/03/2022If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.openwall.com/lists/oss-security/2022/03/14/2](http://www.openwall.com/lists/oss-security/2022/03/14/2)
* [https://security.netapp.com/advisory/ntap-20220321-0001/](https://security.netapp.com/advisory/ntap-20220321-0001/)
* [https://lists.debian.org/debian-lts-announce/2022/03/msg00033.html](https://lists.debian.org/debian-lts-announce/2022/03/msg00033.html)
* [https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html)
* [https://support.apple.com/kb/HT213256](https://support.apple.com/kb/HT213256)
* [https://support.apple.com/kb/HT213257](https://support.apple.com/kb/HT213257)
* [https://support.apple.com/kb/HT213255](https://support.apple.com/kb/HT213255)
* [http://seclists.org/fulldisclosure/2022/May/38](http://seclists.org/fulldisclosure/2022/May/38)
* [http://seclists.org/fulldisclosure/2022/May/33](http://seclists.org/fulldisclosure/2022/May/33)
* [http://seclists.org/fulldisclosure/2022/May/35](http://seclists.org/fulldisclosure/2022/May/35)
* [https://www.oracle.com/security-alerts/cpujul2022.html](https://www.oracle.com/security-alerts/cpujul2022.html)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/) -
Critique CVE-2022-28615 Signalée 09/06/2022Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.openwall.com/lists/oss-security/2022/06/08/9](http://www.openwall.com/lists/oss-security/2022/06/08/9)
* [https://security.netapp.com/advisory/ntap-20220624-0005/](https://security.netapp.com/advisory/ntap-20220624-0005/)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/) -
Critique CVE-2022-31813 Signalée 09/06/2022Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.openwall.com/lists/oss-security/2022/06/08/8](http://www.openwall.com/lists/oss-security/2022/06/08/8)
* [https://security.netapp.com/advisory/ntap-20220624-0005/](https://security.netapp.com/advisory/ntap-20220624-0005/)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/) -
Critique CVE-2026-28780 Signalée 05/05/2026Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
* [http://www.openwall.com/lists/oss-security/2026/05/05/9](http://www.openwall.com/lists/oss-security/2026/05/05/9)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Critique CVE-2026-42535 Signalée 08/06/2026A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
* [http://www.openwall.com/lists/oss-security/2026/06/08/8](http://www.openwall.com/lists/oss-security/2026/06/08/8)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Haute CVE-2006-20001 Signalée 17/01/2023A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://security.gentoo.org/glsa/202309-01](https://security.gentoo.org/glsa/202309-01) -
Haute CVE-2006-3747 Signalée 28/07/2006Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
* [http://www.apache.org/dist/httpd/Announcement2.0.html](http://www.apache.org/dist/httpd/Announcement2.0.html)
* [http://svn.apache.org/viewvc?view=rev&revision=426144](http://svn.apache.org/viewvc?view=rev&revision=426144)
* [http://www.kb.cert.org/vuls/id/395412](http://www.kb.cert.org/vuls/id/395412)
* [http://www.ubuntu.com/usn/usn-328-1](http://www.ubuntu.com/usn/usn-328-1)
* [http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048267.html](http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048267.html)
* [http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048271.html](http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/048271.html)
* [http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.015-apache.html](http://www.openpkg.org/security/advisories/OpenPKG-SA-2006.015-apache.html)
* [http://www.novell.com/linux/security/advisories/2006_43_apache.html](http://www.novell.com/linux/security/advisories/2006_43_apache.html)
* [http://www.securityfocus.com/bid/19204](http://www.securityfocus.com/bid/19204)
* [http://securitytracker.com/id?1016601](http://securitytracker.com/id?1016601)
* [http://secunia.com/advisories/21197](http://secunia.com/advisories/21197)
* [http://secunia.com/advisories/21241](http://secunia.com/advisories/21241)
* [http://kbase.redhat.com/faq/FAQ_68_8653.shtm](http://kbase.redhat.com/faq/FAQ_68_8653.shtm)
* [http://www.debian.org/security/2006/dsa-1131](http://www.debian.org/security/2006/dsa-1131)
* [http://www.debian.org/security/2006/dsa-1132](http://www.debian.org/security/2006/dsa-1132)
* [http://security.gentoo.org/glsa/glsa-200608-01.xml](http://security.gentoo.org/glsa/glsa-200608-01.xml)
* [http://secunia.com/advisories/21245](http://secunia.com/advisories/21245)
* [http://secunia.com/advisories/21266](http://secunia.com/advisories/21266)
* [http://secunia.com/advisories/21273](http://secunia.com/advisories/21273)
* [http://secunia.com/advisories/21284](http://secunia.com/advisories/21284)
* [http://secunia.com/advisories/21313](http://secunia.com/advisories/21313)
* [https://issues.rpath.com/browse/RPL-538](https://issues.rpath.com/browse/RPL-538)
* [http://www-1.ibm.com/support/docview.wss?uid=swg24013080](http://www-1.ibm.com/support/docview.wss?uid=swg24013080)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK29154](http://www-1.ibm.com/support/docview.wss?uid=swg1PK29154)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK29156](http://www-1.ibm.com/support/docview.wss?uid=swg1PK29156)
* [http://www.osvdb.org/27588](http://www.osvdb.org/27588)
* [http://secunia.com/advisories/21307](http://secunia.com/advisories/21307)
* [http://secunia.com/advisories/21315](http://secunia.com/advisories/21315)
* [http://secunia.com/advisories/21247](http://secunia.com/advisories/21247)
* [http://secunia.com/advisories/21478](http://secunia.com/advisories/21478)
* [http://secunia.com/advisories/21509](http://secunia.com/advisories/21509)
* [http://secunia.com/advisories/22262](http://secunia.com/advisories/22262)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1)
* [http://secunia.com/advisories/22368](http://secunia.com/advisories/22368)
* [http://secunia.com/advisories/22388](http://secunia.com/advisories/22388)
* [http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3117](http://www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjd?mode=18&ID=3117)
* [http://secunia.com/advisories/22523](http://secunia.com/advisories/22523)
* [http://www-1.ibm.com/support/docview.wss?uid=swg27007951](http://www-1.ibm.com/support/docview.wss?uid=swg27007951)
* [http://secunia.com/advisories/23028](http://secunia.com/advisories/23028)
* [http://secunia.com/advisories/23260](http://secunia.com/advisories/23260)
* [http://lwn.net/Alerts/194228/](http://lwn.net/Alerts/194228/)
* [http://secunia.com/advisories/21346](http://secunia.com/advisories/21346)
* [http://www.mandriva.com/security/advisories?name=MDKSA-2006:133](http://www.mandriva.com/security/advisories?name=MDKSA-2006:133)
* [http://secunia.com/advisories/26329](http://secunia.com/advisories/26329)
* [http://securityreason.com/securityalert/1312](http://securityreason.com/securityalert/1312)
* [http://docs.info.apple.com/article.html?artnum=307562](http://docs.info.apple.com/article.html?artnum=307562)
* [http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html](http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html)
* [http://secunia.com/advisories/29420](http://secunia.com/advisories/29420)
* [http://secunia.com/advisories/29849](http://secunia.com/advisories/29849)
* [http://lists.apple.com/archives/security-announce/2008//May/msg00001.html](http://lists.apple.com/archives/security-announce/2008//May/msg00001.html)
* [http://www.us-cert.gov/cas/techalerts/TA08-150A.html](http://www.us-cert.gov/cas/techalerts/TA08-150A.html)
* [http://secunia.com/advisories/30430](http://secunia.com/advisories/30430)
* [http://www.vupen.com/english/advisories/2008/1697](http://www.vupen.com/english/advisories/2008/1697)
* [http://www.vupen.com/english/advisories/2006/3995](http://www.vupen.com/english/advisories/2006/3995)
* [http://www.vupen.com/english/advisories/2006/4300](http://www.vupen.com/english/advisories/2006/4300)
* [http://www.vupen.com/english/advisories/2006/3017](http://www.vupen.com/english/advisories/2006/3017)
* [http://www.vupen.com/english/advisories/2006/3264](http://www.vupen.com/english/advisories/2006/3264)
* [http://www.vupen.com/english/advisories/2008/0924/references](http://www.vupen.com/english/advisories/2008/0924/references)
* [http://www.vupen.com/english/advisories/2006/4207](http://www.vupen.com/english/advisories/2006/4207)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449)
* [http://www.vupen.com/english/advisories/2007/2783](http://www.vupen.com/english/advisories/2007/2783)
* [http://www.vupen.com/english/advisories/2006/3282](http://www.vupen.com/english/advisories/2006/3282)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771)
* [http://www.vupen.com/english/advisories/2006/4015](http://www.vupen.com/english/advisories/2006/4015)
* [http://www.vupen.com/english/advisories/2006/4868](http://www.vupen.com/english/advisories/2006/4868)
* [http://www.vupen.com/english/advisories/2008/1246/references](http://www.vupen.com/english/advisories/2008/1246/references)
* [http://www.vupen.com/english/advisories/2006/3884](http://www.vupen.com/english/advisories/2006/3884)
* [http://marc.info/?l=bugtraq&m=130497311408250&w=2](http://marc.info/?l=bugtraq&m=130497311408250&w=2)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/28063](https://exchange.xforce.ibmcloud.com/vulnerabilities/28063)
* [http://www.securityfocus.com/archive/1/450321/100/0/threaded](http://www.securityfocus.com/archive/1/450321/100/0/threaded)
* [http://www.securityfocus.com/archive/1/445206/100/0/threaded](http://www.securityfocus.com/archive/1/445206/100/0/threaded)
* [http://www.securityfocus.com/archive/1/443870/100/0/threaded](http://www.securityfocus.com/archive/1/443870/100/0/threaded)
* [http://www.securityfocus.com/archive/1/441526/100/200/threaded](http://www.securityfocus.com/archive/1/441526/100/200/threaded)
* [http://www.securityfocus.com/archive/1/441487/100/0/threaded](http://www.securityfocus.com/archive/1/441487/100/0/threaded)
* [http://www.securityfocus.com/archive/1/441485/100/0/threaded](http://www.securityfocus.com/archive/1/441485/100/0/threaded)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2009-1890 Signalée 05/07/2009The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?revision=790587](http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?revision=790587)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=790587&r2=790586&pathrev=790587](http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=790587&r2=790586&pathrev=790587)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=790587&r2=790586&pathrev=790587](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=790587&r2=790586&pathrev=790587)
* [http://secunia.com/advisories/35691](http://secunia.com/advisories/35691)
* [http://svn.apache.org/viewvc?view=rev&revision=790587](http://svn.apache.org/viewvc?view=rev&revision=790587)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:149](http://www.mandriva.com/security/advisories?name=MDVSA-2009:149)
* [https://rhn.redhat.com/errata/RHSA-2009-1148.html](https://rhn.redhat.com/errata/RHSA-2009-1148.html)
* [http://www.securitytracker.com/id?1022509](http://www.securitytracker.com/id?1022509)
* [http://osvdb.org/55553](http://osvdb.org/55553)
* [http://www.redhat.com/support/errata/RHSA-2009-1156.html](http://www.redhat.com/support/errata/RHSA-2009-1156.html)
* [http://www.securityfocus.com/bid/35565](http://www.securityfocus.com/bid/35565)
* [http://security.gentoo.org/glsa/glsa-200907-04.xml](http://security.gentoo.org/glsa/glsa-200907-04.xml)
* [http://secunia.com/advisories/35721](http://secunia.com/advisories/35721)
* [http://www.ubuntu.com/usn/USN-802-1](http://www.ubuntu.com/usn/USN-802-1)
* [http://secunia.com/advisories/35793](http://secunia.com/advisories/35793)
* [http://www.debian.org/security/2009/dsa-1834](http://www.debian.org/security/2009/dsa-1834)
* [http://secunia.com/advisories/35865](http://secunia.com/advisories/35865)
* [https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html](https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html)
* [http://secunia.com/advisories/37152](http://secunia.com/advisories/37152)
* [http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html)
* [http://support.apple.com/kb/HT3937](http://support.apple.com/kb/HT3937)
* [http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html](http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html)
* [http://www.vupen.com/english/advisories/2009/3184](http://www.vupen.com/english/advisories/2009/3184)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK99480](http://www-01.ibm.com/support/docview.wss?uid=swg1PK99480)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK91259](http://www-01.ibm.com/support/docview.wss?uid=swg1PK91259)
* [http://secunia.com/advisories/37221](http://secunia.com/advisories/37221)
* [http://wiki.rpath.com/Advisories:rPSA-2009-0142](http://wiki.rpath.com/Advisories:rPSA-2009-0142)
* [http://marc.info/?l=bugtraq&m=129190899612998&w=2](http://marc.info/?l=bugtraq&m=129190899612998&w=2)
* [http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html](http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9403](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9403)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8616](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8616)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12330](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12330)
* [http://www.securityfocus.com/archive/1/507857/100/0/threaded](http://www.securityfocus.com/archive/1/507857/100/0/threaded)
* [http://www.securityfocus.com/archive/1/507852/100/0/threaded](http://www.securityfocus.com/archive/1/507852/100/0/threaded)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb33be0aa9bd8cac9536293e3821dcd4cf8180ad95a8036eedd46365e%40%3Cusers.mina.apache.org%3E](https://lists.apache.org/thread.html/rb33be0aa9bd8cac9536293e3821dcd4cf8180ad95a8036eedd46365e%40%3Cusers.mina.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2009-1891 Signalée 10/07/2009The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
* [http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534712](http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534712)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:149](http://www.mandriva.com/security/advisories?name=MDVSA-2009:149)
* [https://bugzilla.redhat.com/show_bug.cgi?id=509125](https://bugzilla.redhat.com/show_bug.cgi?id=509125)
* [http://marc.info/?l=apache-httpd-dev&m=124661528519546&w=2](http://marc.info/?l=apache-httpd-dev&m=124661528519546&w=2)
* [https://rhn.redhat.com/errata/RHSA-2009-1148.html](https://rhn.redhat.com/errata/RHSA-2009-1148.html)
* [http://marc.info/?l=apache-httpd-dev&m=124621326524824&w=2](http://marc.info/?l=apache-httpd-dev&m=124621326524824&w=2)
* [http://secunia.com/advisories/35865](http://secunia.com/advisories/35865)
* [http://www.debian.org/security/2009/dsa-1834](http://www.debian.org/security/2009/dsa-1834)
* [http://www.redhat.com/support/errata/RHSA-2009-1156.html](http://www.redhat.com/support/errata/RHSA-2009-1156.html)
* [http://www.securitytracker.com/id?1022529](http://www.securitytracker.com/id?1022529)
* [http://secunia.com/advisories/35781](http://secunia.com/advisories/35781)
* [http://secunia.com/advisories/35793](http://secunia.com/advisories/35793)
* [http://secunia.com/advisories/35721](http://secunia.com/advisories/35721)
* [http://www.vupen.com/english/advisories/2009/1841](http://www.vupen.com/english/advisories/2009/1841)
* [http://security.gentoo.org/glsa/glsa-200907-04.xml](http://security.gentoo.org/glsa/glsa-200907-04.xml)
* [http://osvdb.org/55782](http://osvdb.org/55782)
* [http://www.ubuntu.com/usn/USN-802-1](http://www.ubuntu.com/usn/USN-802-1)
* [https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html](https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01363.html)
* [http://secunia.com/advisories/37152](http://secunia.com/advisories/37152)
* [http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html)
* [http://support.apple.com/kb/HT3937](http://support.apple.com/kb/HT3937)
* [http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html](http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html)
* [http://www.vupen.com/english/advisories/2009/3184](http://www.vupen.com/english/advisories/2009/3184)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK91361](http://www-01.ibm.com/support/docview.wss?uid=swg1PK91361)
* [http://secunia.com/advisories/37221](http://secunia.com/advisories/37221)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK99480](http://www-01.ibm.com/support/docview.wss?uid=swg1PK99480)
* [http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0142](http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0142)
* [http://wiki.rpath.com/Advisories:rPSA-2009-0142](http://wiki.rpath.com/Advisories:rPSA-2009-0142)
* [http://marc.info/?l=bugtraq&m=129190899612998&w=2](http://marc.info/?l=bugtraq&m=129190899612998&w=2)
* [http://marc.info/?l=bugtraq&m=130497311408250&w=2](http://marc.info/?l=bugtraq&m=130497311408250&w=2)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9248](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9248)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8632](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8632)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12361](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12361)
* [http://www.securityfocus.com/archive/1/507857/100/0/threaded](http://www.securityfocus.com/archive/1/507857/100/0/threaded)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2009-1955 Signalée 08/06/2009The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.
* [http://svn.apache.org/viewvc?view=rev&revision=781403](http://svn.apache.org/viewvc?view=rev&revision=781403)
* [http://www.debian.org/security/2009/dsa-1812](http://www.debian.org/security/2009/dsa-1812)
* [http://secunia.com/advisories/35284](http://secunia.com/advisories/35284)
* [http://marc.info/?l=apr-dev&m=124396021826125&w=2](http://marc.info/?l=apr-dev&m=124396021826125&w=2)
* [http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3](http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3)
* [http://secunia.com/advisories/35360](http://secunia.com/advisories/35360)
* [http://www.openwall.com/lists/oss-security/2009/06/03/4](http://www.openwall.com/lists/oss-security/2009/06/03/4)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:131](http://www.mandriva.com/security/advisories?name=MDVSA-2009:131)
* [http://www.securityfocus.com/bid/35253](http://www.securityfocus.com/bid/35253)
* [http://www.ubuntu.com/usn/usn-786-1](http://www.ubuntu.com/usn/usn-786-1)
* [http://www.redhat.com/support/errata/RHSA-2009-1108.html](http://www.redhat.com/support/errata/RHSA-2009-1108.html)
* [http://www.redhat.com/support/errata/RHSA-2009-1107.html](http://www.redhat.com/support/errata/RHSA-2009-1107.html)
* [http://secunia.com/advisories/35487](http://secunia.com/advisories/35487)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.538210](http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.538210)
* [http://secunia.com/advisories/35444](http://secunia.com/advisories/35444)
* [http://secunia.com/advisories/34724](http://secunia.com/advisories/34724)
* [http://secunia.com/advisories/35395](http://secunia.com/advisories/35395)
* [http://www.ubuntu.com/usn/usn-787-1](http://www.ubuntu.com/usn/usn-787-1)
* [https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html](https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html](https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html](https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html)
* [http://secunia.com/advisories/35565](http://secunia.com/advisories/35565)
* [http://secunia.com/advisories/35797](http://secunia.com/advisories/35797)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK88342](http://www-01.ibm.com/support/docview.wss?uid=swg1PK88342)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241](http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241)
* [http://secunia.com/advisories/35710](http://secunia.com/advisories/35710)
* [http://secunia.com/advisories/35843](http://secunia.com/advisories/35843)
* [http://security.gentoo.org/glsa/glsa-200907-03.xml](http://security.gentoo.org/glsa/glsa-200907-03.xml)
* [http://www.vupen.com/english/advisories/2009/1907](http://www.vupen.com/english/advisories/2009/1907)
* [http://secunia.com/advisories/36473](http://secunia.com/advisories/36473)
* [http://wiki.rpath.com/Advisories:rPSA-2009-0123](http://wiki.rpath.com/Advisories:rPSA-2009-0123)
* [http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html](http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html)
* [http://support.apple.com/kb/HT3937](http://support.apple.com/kb/HT3937)
* [http://www.vupen.com/english/advisories/2009/3184](http://www.vupen.com/english/advisories/2009/3184)
* [http://www-01.ibm.com/support/docview.wss?uid=swg27014463](http://www-01.ibm.com/support/docview.wss?uid=swg27014463)
* [http://secunia.com/advisories/37221](http://secunia.com/advisories/37221)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478](http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478)
* [http://www.vupen.com/english/advisories/2010/1107](http://www.vupen.com/english/advisories/2010/1107)
* [http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html)
* [http://marc.info/?l=bugtraq&m=129190899612998&w=2](http://marc.info/?l=bugtraq&m=129190899612998&w=2)
* [http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html](http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [https://www.exploit-db.com/exploits/8842](https://www.exploit-db.com/exploits/8842)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12473](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12473)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10270](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10270)
* [http://www.securityfocus.com/archive/1/506053/100/0/threaded](http://www.securityfocus.com/archive/1/506053/100/0/threaded)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2009-2699 Signalée 13/10/2009The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.
* [http://www.securityfocus.com/bid/36596](http://www.securityfocus.com/bid/36596)
* [http://www.apache.org/dist/httpd/CHANGES_2.2.14](http://www.apache.org/dist/httpd/CHANGES_2.2.14)
* [http://securitytracker.com/id?1022988](http://securitytracker.com/id?1022988)
* [https://issues.apache.org/bugzilla/show_bug.cgi?id=47645](https://issues.apache.org/bugzilla/show_bug.cgi?id=47645)
* [http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html](http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [http://marc.info/?l=bugtraq&m=133355494609819&w=2](http://marc.info/?l=bugtraq&m=133355494609819&w=2)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/53666](https://exchange.xforce.ibmcloud.com/vulnerabilities/53666)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2010-0425 Signalée 05/03/2010modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
* [http://httpd.apache.org/security/vulnerabilities_20.html](http://httpd.apache.org/security/vulnerabilities_20.html)
* [http://httpd.apache.org/security/vulnerabilities_20.html](http://httpd.apache.org/security/vulnerabilities_20.html)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://lists.vmware.com/pipermail/security-announce/2010/000105.html](http://lists.vmware.com/pipermail/security-announce/2010/000105.html)
* [http://lists.vmware.com/pipermail/security-announce/2010/000105.html](http://lists.vmware.com/pipermail/security-announce/2010/000105.html)
* [http://secunia.com/advisories/38978](http://secunia.com/advisories/38978)
* [http://secunia.com/advisories/38978](http://secunia.com/advisories/38978)
* [http://secunia.com/advisories/39628](http://secunia.com/advisories/39628)
* [http://secunia.com/advisories/39628](http://secunia.com/advisories/39628)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&r2=917869&pathrev=917870](http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&r2=917869&pathrev=917870)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&r2=917869&pathrev=917870](http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=917870&r2=917869&pathrev=917870)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&r2=917869&pathrev=917870](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&r2=917869&pathrev=917870)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&r2=917869&pathrev=917870](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/arch/win32/mod_isapi.c?r1=917870&r2=917869&pathrev=917870)
* [http://svn.apache.org/viewvc?view=revision&revision=917870](http://svn.apache.org/viewvc?view=revision&revision=917870)
* [http://svn.apache.org/viewvc?view=revision&revision=917870](http://svn.apache.org/viewvc?view=revision&revision=917870)
* [http://www.kb.cert.org/vuls/id/280613](http://www.kb.cert.org/vuls/id/280613)
* [http://www.kb.cert.org/vuls/id/280613](http://www.kb.cert.org/vuls/id/280613)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [http://www.securityfocus.com/bid/38494](http://www.securityfocus.com/bid/38494)
* [http://www.securityfocus.com/bid/38494](http://www.securityfocus.com/bid/38494)
* [http://www.securitytracker.com/id?1023701](http://www.securitytracker.com/id?1023701)
* [http://www.securitytracker.com/id?1023701](http://www.securitytracker.com/id?1023701)
* [http://www.senseofsecurity.com.au/advisories/SOS-10-002](http://www.senseofsecurity.com.au/advisories/SOS-10-002)
* [http://www.senseofsecurity.com.au/advisories/SOS-10-002](http://www.senseofsecurity.com.au/advisories/SOS-10-002)
* [http://www.vmware.com/security/advisories/VMSA-2010-0014.html](http://www.vmware.com/security/advisories/VMSA-2010-0014.html)
* [http://www.vmware.com/security/advisories/VMSA-2010-0014.html](http://www.vmware.com/security/advisories/VMSA-2010-0014.html)
* [http://www.vupen.com/english/advisories/2010/0634](http://www.vupen.com/english/advisories/2010/0634)
* [http://www.vupen.com/english/advisories/2010/0634](http://www.vupen.com/english/advisories/2010/0634)
* [http://www.vupen.com/english/advisories/2010/0994](http://www.vupen.com/english/advisories/2010/0994)
* [http://www.vupen.com/english/advisories/2010/0994](http://www.vupen.com/english/advisories/2010/0994)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM09447](http://www-01.ibm.com/support/docview.wss?uid=swg1PM09447)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM09447](http://www-01.ibm.com/support/docview.wss?uid=swg1PM09447)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247](http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247](http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/56624](https://exchange.xforce.ibmcloud.com/vulnerabilities/56624)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/56624](https://exchange.xforce.ibmcloud.com/vulnerabilities/56624)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8439](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8439)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8439](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8439)
* [https://www.exploit-db.com/exploits/11650](https://www.exploit-db.com/exploits/11650)
* [https://www.exploit-db.com/exploits/11650](https://www.exploit-db.com/exploits/11650) -
Haute CVE-2011-3192 Signalée 29/08/2011The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.
* [http://www.exploit-db.com/exploits/17696](http://www.exploit-db.com/exploits/17696)
* [http://secunia.com/advisories/45606](http://secunia.com/advisories/45606)
* [https://bugzilla.redhat.com/show_bug.cgi?id=732928](https://bugzilla.redhat.com/show_bug.cgi?id=732928)
* [http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.html](http://archives.neohapsis.com/archives/fulldisclosure/2011-08/0285.html)
* [https://issues.apache.org/bugzilla/show_bug.cgi?id=51714](https://issues.apache.org/bugzilla/show_bug.cgi?id=51714)
* [http://www.gossamer-threads.com/lists/apache/dev/401638](http://www.gossamer-threads.com/lists/apache/dev/401638)
* [http://securitytracker.com/id?1025960](http://securitytracker.com/id?1025960)
* [http://seclists.org/fulldisclosure/2011/Aug/175](http://seclists.org/fulldisclosure/2011/Aug/175)
* [http://www.securityfocus.com/bid/49303](http://www.securityfocus.com/bid/49303)
* [http://osvdb.org/74721](http://osvdb.org/74721)
* [http://blogs.oracle.com/security/entry/security_alert_for_cve_2011](http://blogs.oracle.com/security/entry/security_alert_for_cve_2011)
* [http://www.ubuntu.com/usn/USN-1199-1](http://www.ubuntu.com/usn/USN-1199-1)
* [http://www.redhat.com/support/errata/RHSA-2011-1294.html](http://www.redhat.com/support/errata/RHSA-2011-1294.html)
* [http://www.apache.org/dist/httpd/Announcement2.2.html](http://www.apache.org/dist/httpd/Announcement2.2.html)
* [http://secunia.com/advisories/46000](http://secunia.com/advisories/46000)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2011:130](http://www.mandriva.com/security/advisories?name=MDVSA-2011:130)
* [http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192-485304.html](http://www.oracle.com/technetwork/topics/security/alert-cve-2011-3192-485304.html)
* [http://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtml](http://www.cisco.com/en/US/products/products_security_advisory09186a0080b90d73.shtml)
* [http://secunia.com/advisories/45937](http://secunia.com/advisories/45937)
* [http://www.redhat.com/support/errata/RHSA-2011-1245.html](http://www.redhat.com/support/errata/RHSA-2011-1245.html)
* [http://www.redhat.com/support/errata/RHSA-2011-1300.html](http://www.redhat.com/support/errata/RHSA-2011-1300.html)
* [http://secunia.com/advisories/46126](http://secunia.com/advisories/46126)
* [http://www.kb.cert.org/vuls/id/405811](http://www.kb.cert.org/vuls/id/405811)
* [http://www.redhat.com/support/errata/RHSA-2011-1330.html](http://www.redhat.com/support/errata/RHSA-2011-1330.html)
* [http://secunia.com/advisories/46125](http://secunia.com/advisories/46125)
* [http://www.redhat.com/support/errata/RHSA-2011-1329.html](http://www.redhat.com/support/errata/RHSA-2011-1329.html)
* [http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html](http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html)
* [http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html](http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html)
* [http://support.apple.com/kb/HT5002](http://support.apple.com/kb/HT5002)
* [http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html](http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html)
* [http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00006.html)
* [http://marc.info/?l=bugtraq&m=131551295528105&w=2](http://marc.info/?l=bugtraq&m=131551295528105&w=2)
* [http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.html](http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00011.html)
* [http://marc.info/?l=bugtraq&m=131731002122529&w=2](http://marc.info/?l=bugtraq&m=131731002122529&w=2)
* [http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.html](http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00010.html)
* [http://www.redhat.com/support/errata/RHSA-2011-1369.html](http://www.redhat.com/support/errata/RHSA-2011-1369.html)
* [http://marc.info/?l=bugtraq&m=132033751509019&w=2](http://marc.info/?l=bugtraq&m=132033751509019&w=2)
* [http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.html](http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.html)
* [http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html](http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html)
* [http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html](http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html)
* [http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html](http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html)
* [http://marc.info/?l=bugtraq&m=134987041210674&w=2](http://marc.info/?l=bugtraq&m=134987041210674&w=2)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [http://marc.info/?l=bugtraq&m=133951357207000&w=2](http://marc.info/?l=bugtraq&m=133951357207000&w=2)
* [http://marc.info/?l=bugtraq&m=133477473521382&w=2](http://marc.info/?l=bugtraq&m=133477473521382&w=2)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/69396](https://exchange.xforce.ibmcloud.com/vulnerabilities/69396)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18827](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18827)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14824](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14824)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14762](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14762)
* [https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0](https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0)
* [http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g%40mail.gmail.com%3e](http://mail-archives.apache.org/mod_mbox/httpd-dev/201108.mbox/%3cCAAPSnn2PO-d-C4nQt_TES2RRWiZr7urefhTKPWBC1b+K1Dqc7g%40mail.gmail.com%3e)
* [http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122D387DD%40minotaur.apache.org%3e](http://mail-archives.apache.org/mod_mbox/httpd-announce/201108.mbox/%3c20110824161640.122D387DD%40minotaur.apache.org%3e)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2016-5387 Signalée 19/07/2016The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
* [http://www.kb.cert.org/vuls/id/797896](http://www.kb.cert.org/vuls/id/797896)
* [https://httpoxy.org/](https://httpoxy.org/)
* [https://www.apache.org/security/asf-httpoxy-response.txt](https://www.apache.org/security/asf-httpoxy-response.txt)
* [http://www.securitytracker.com/id/1036330](http://www.securitytracker.com/id/1036330)
* [http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html](http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html)
* [http://rhn.redhat.com/errata/RHSA-2016-1650.html](http://rhn.redhat.com/errata/RHSA-2016-1650.html)
* [http://rhn.redhat.com/errata/RHSA-2016-1648.html](http://rhn.redhat.com/errata/RHSA-2016-1648.html)
* [http://rhn.redhat.com/errata/RHSA-2016-1649.html](http://rhn.redhat.com/errata/RHSA-2016-1649.html)
* [http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html](http://www.oracle.com/technetwork/topics/security/bulletinoct2016-3090566.html)
* [https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149](https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149)
* [http://lists.opensuse.org/opensuse-updates/2016-07/msg00059.html](http://lists.opensuse.org/opensuse-updates/2016-07/msg00059.html)
* [https://access.redhat.com/errata/RHSA-2016:1635](https://access.redhat.com/errata/RHSA-2016:1635)
* [http://rhn.redhat.com/errata/RHSA-2016-1625.html](http://rhn.redhat.com/errata/RHSA-2016-1625.html)
* [https://access.redhat.com/errata/RHSA-2016:1422](https://access.redhat.com/errata/RHSA-2016:1422)
* [https://access.redhat.com/errata/RHSA-2016:1851](https://access.redhat.com/errata/RHSA-2016:1851)
* [https://access.redhat.com/errata/RHSA-2016:1421](https://access.redhat.com/errata/RHSA-2016:1421)
* [https://access.redhat.com/errata/RHSA-2016:1420](https://access.redhat.com/errata/RHSA-2016:1420)
* [http://www.securityfocus.com/bid/91816](http://www.securityfocus.com/bid/91816)
* [http://www.ubuntu.com/usn/USN-3038-1](http://www.ubuntu.com/usn/USN-3038-1)
* [http://rhn.redhat.com/errata/RHSA-2016-1624.html](http://rhn.redhat.com/errata/RHSA-2016-1624.html)
* [https://access.redhat.com/errata/RHSA-2016:1636](https://access.redhat.com/errata/RHSA-2016:1636)
* [https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722](https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722)
* [http://www.debian.org/security/2016/dsa-3623](http://www.debian.org/security/2016/dsa-3623)
* [https://security.gentoo.org/glsa/201701-36](https://security.gentoo.org/glsa/201701-36)
* [http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html](http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html)
* [https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us](https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us)
* [https://www.tenable.com/security/tns-2017-04](https://www.tenable.com/security/tns-2017-04)
* [https://support.apple.com/HT208221](https://support.apple.com/HT208221)
* [http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html](http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WCTE7443AYZ4EGELWLVNANA2WJCJIYI/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WCTE7443AYZ4EGELWLVNANA2WJCJIYI/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGNHXJJSWDXAOEYH5TMXDPQVJMQQJOAZ/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TGNHXJJSWDXAOEYH5TMXDPQVJMQQJOAZ/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEKZAB7MTWVSMORHTEMCQNFFMIHCYF76/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEKZAB7MTWVSMORHTEMCQNFFMIHCYF76/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QPQAPWQA774JPDRV4UIB2SZAX6D3UZCV/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QPQAPWQA774JPDRV4UIB2SZAX6D3UZCV/)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2016-8743 Signalée 27/07/2017Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.
* [https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2016-8743](https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2016-8743)
* [https://security.gentoo.org/glsa/201701-36](https://security.gentoo.org/glsa/201701-36)
* [https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03725en_us](https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03725en_us)
* [http://www.securitytracker.com/id/1037508](http://www.securitytracker.com/id/1037508)
* [http://www.securityfocus.com/bid/95077](http://www.securityfocus.com/bid/95077)
* [https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu03753en_us](https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu03753en_us)
* [https://www.tenable.com/security/tns-2017-04](https://www.tenable.com/security/tns-2017-04)
* [http://www.debian.org/security/2017/dsa-3796](http://www.debian.org/security/2017/dsa-3796)
* [https://support.apple.com/HT208221](https://support.apple.com/HT208221)
* [https://access.redhat.com/errata/RHSA-2017:1721](https://access.redhat.com/errata/RHSA-2017:1721)
* [https://access.redhat.com/errata/RHSA-2017:1414](https://access.redhat.com/errata/RHSA-2017:1414)
* [https://access.redhat.com/errata/RHSA-2017:1413](https://access.redhat.com/errata/RHSA-2017:1413)
* [https://access.redhat.com/errata/RHSA-2017:1161](https://access.redhat.com/errata/RHSA-2017:1161)
* [https://access.redhat.com/errata/RHSA-2017:0906](https://access.redhat.com/errata/RHSA-2017:0906)
* [http://rhn.redhat.com/errata/RHSA-2017-1415.html](http://rhn.redhat.com/errata/RHSA-2017-1415.html)
* [https://security.netapp.com/advisory/ntap-20180423-0001/](https://security.netapp.com/advisory/ntap-20180423-0001/)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re1e3a24664d35bcd0a0e793e0b5fc6ca6c107f99a1b2c545c5d4b467%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r04e89e873d54116a0635ef2f7061c15acc5ed27ef7500997beb65d6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r94284b139540e5287ebdd3450682d3e3d187263dd6b75af8fa7d4890%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r94284b139540e5287ebdd3450682d3e3d187263dd6b75af8fa7d4890%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r4fe84db67fe9dc906c6185e58bbd9913f4356dd555a5c3db490694e5%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r4fe84db67fe9dc906c6185e58bbd9913f4356dd555a5c3db490694e5%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r09b8a39d1262adbab5528eea73df1b1f93e919bf004ed5a843d9cad1%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r09b8a39d1262adbab5528eea73df1b1f93e919bf004ed5a843d9cad1%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfcb6c7b9e7ca727a7eeeb5f13f89488a03981cfa0e7c3125f18fa239%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfcb6c7b9e7ca727a7eeeb5f13f89488a03981cfa0e7c3125f18fa239%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2017-9798 Signalée 18/09/2017Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.
* [https://security-tracker.debian.org/tracker/CVE-2017-9798](https://security-tracker.debian.org/tracker/CVE-2017-9798)
* [https://github.com/hannob/optionsbleed](https://github.com/hannob/optionsbleed)
* [https://blog.fuzzing-project.org/uploads/apache-2.2-optionsbleed-backport.patch](https://blog.fuzzing-project.org/uploads/apache-2.2-optionsbleed-backport.patch)
* [https://blog.fuzzing-project.org/60-Optionsbleed-HTTP-OPTIONS-method-can-leak-Apaches-server-memory.html](https://blog.fuzzing-project.org/60-Optionsbleed-HTTP-OPTIONS-method-can-leak-Apaches-server-memory.html)
* [http://openwall.com/lists/oss-security/2017/09/18/2](http://openwall.com/lists/oss-security/2017/09/18/2)
* [https://svn.apache.org/viewvc/httpd/httpd/branches/2.4.x/server/core.c?r1=1805223&r2=1807754&pathrev=1807754&view=patch](https://svn.apache.org/viewvc/httpd/httpd/branches/2.4.x/server/core.c?r1=1805223&r2=1807754&pathrev=1807754&view=patch)
* [https://www.exploit-db.com/exploits/42745/](https://www.exploit-db.com/exploits/42745/)
* [http://www.securitytracker.com/id/1039387](http://www.securitytracker.com/id/1039387)
* [http://www.securityfocus.com/bid/100872](http://www.securityfocus.com/bid/100872)
* [https://security.gentoo.org/glsa/201710-32](https://security.gentoo.org/glsa/201710-32)
* [http://www.debian.org/security/2017/dsa-3980](http://www.debian.org/security/2017/dsa-3980)
* [https://access.redhat.com/errata/RHSA-2017:3240](https://access.redhat.com/errata/RHSA-2017:3240)
* [https://access.redhat.com/errata/RHSA-2017:3239](https://access.redhat.com/errata/RHSA-2017:3239)
* [https://access.redhat.com/errata/RHSA-2017:3195](https://access.redhat.com/errata/RHSA-2017:3195)
* [https://access.redhat.com/errata/RHSA-2017:3194](https://access.redhat.com/errata/RHSA-2017:3194)
* [https://access.redhat.com/errata/RHSA-2017:3193](https://access.redhat.com/errata/RHSA-2017:3193)
* [https://access.redhat.com/errata/RHSA-2017:3114](https://access.redhat.com/errata/RHSA-2017:3114)
* [https://access.redhat.com/errata/RHSA-2017:3113](https://access.redhat.com/errata/RHSA-2017:3113)
* [https://access.redhat.com/errata/RHSA-2017:3018](https://access.redhat.com/errata/RHSA-2017:3018)
* [https://access.redhat.com/errata/RHSA-2017:2972](https://access.redhat.com/errata/RHSA-2017:2972)
* [https://access.redhat.com/errata/RHSA-2017:2882](https://access.redhat.com/errata/RHSA-2017:2882)
* [https://access.redhat.com/errata/RHSA-2017:3477](https://access.redhat.com/errata/RHSA-2017:3477)
* [https://access.redhat.com/errata/RHSA-2017:3476](https://access.redhat.com/errata/RHSA-2017:3476)
* [https://access.redhat.com/errata/RHSA-2017:3475](https://access.redhat.com/errata/RHSA-2017:3475)
* [https://support.apple.com/HT208331](https://support.apple.com/HT208331)
* [http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html](http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html)
* [http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html](http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html)
* [https://security.netapp.com/advisory/ntap-20180601-0003/](https://security.netapp.com/advisory/ntap-20180601-0003/)
* [http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html](http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html)
* [http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html](http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html)
* [http://www.securityfocus.com/bid/105598](http://www.securityfocus.com/bid/105598)
* [https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html](https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html)
* [https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us)
* [https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2017-9798](https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2017-9798)
* [https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html](https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html)
* [https://www.tenable.com/security/tns-2019-09](https://www.tenable.com/security/tns-2019-09)
* [https://github.com/apache/httpd/commit/4cc27823899e070268b906ca677ee838d07cf67a](https://github.com/apache/httpd/commit/4cc27823899e070268b906ca677ee838d07cf67a)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2018-1303 Signalée 26/03/2018A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_disk is not concerned by this vulnerability.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.openwall.com/lists/oss-security/2018/03/24/3](http://www.openwall.com/lists/oss-security/2018/03/24/3)
* [http://www.securitytracker.com/id/1040572](http://www.securitytracker.com/id/1040572)
* [http://www.securityfocus.com/bid/103522](http://www.securityfocus.com/bid/103522)
* [https://www.debian.org/security/2018/dsa-4164](https://www.debian.org/security/2018/dsa-4164)
* [https://usn.ubuntu.com/3627-1/](https://usn.ubuntu.com/3627-1/)
* [https://usn.ubuntu.com/3627-2/](https://usn.ubuntu.com/3627-2/)
* [https://security.netapp.com/advisory/ntap-20180601-0004/](https://security.netapp.com/advisory/ntap-20180601-0004/)
* [https://access.redhat.com/errata/RHSA-2018:3558](https://access.redhat.com/errata/RHSA-2018:3558)
* [https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us)
* [https://access.redhat.com/errata/RHSA-2019:0367](https://access.redhat.com/errata/RHSA-2019:0367)
* [https://access.redhat.com/errata/RHSA-2019:0366](https://access.redhat.com/errata/RHSA-2019:0366)
* [https://www.tenable.com/security/tns-2019-09](https://www.tenable.com/security/tns-2019-09)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E) -
Haute CVE-2021-34798 Signalée 16/09/2021Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
* [http://httpd.apache.org/security/vulnerabilities_24.html](http://httpd.apache.org/security/vulnerabilities_24.html)
* [https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html](https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html)
* [https://security.netapp.com/advisory/ntap-20211008-0004/](https://security.netapp.com/advisory/ntap-20211008-0004/)
* [https://www.debian.org/security/2021/dsa-4982](https://www.debian.org/security/2021/dsa-4982)
* [https://www.tenable.com/security/tns-2021-17](https://www.tenable.com/security/tns-2021-17)
* [https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ)
* [https://www.oracle.com/security-alerts/cpujan2022.html](https://www.oracle.com/security-alerts/cpujan2022.html)
* [https://kc.mcafee.com/corporate/index?page=content&id=SB10379](https://kc.mcafee.com/corporate/index?page=content&id=SB10379)
* [https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html)
* [https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/)
* [https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/) -
Haute CVE-2022-22719 Signalée 14/03/2022A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.openwall.com/lists/oss-security/2022/03/14/4](http://www.openwall.com/lists/oss-security/2022/03/14/4)
* [https://security.netapp.com/advisory/ntap-20220321-0001/](https://security.netapp.com/advisory/ntap-20220321-0001/)
* [https://lists.debian.org/debian-lts-announce/2022/03/msg00033.html](https://lists.debian.org/debian-lts-announce/2022/03/msg00033.html)
* [https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html)
* [https://support.apple.com/kb/HT213256](https://support.apple.com/kb/HT213256)
* [https://support.apple.com/kb/HT213257](https://support.apple.com/kb/HT213257)
* [https://support.apple.com/kb/HT213255](https://support.apple.com/kb/HT213255)
* [http://seclists.org/fulldisclosure/2022/May/38](http://seclists.org/fulldisclosure/2022/May/38)
* [http://seclists.org/fulldisclosure/2022/May/33](http://seclists.org/fulldisclosure/2022/May/33)
* [http://seclists.org/fulldisclosure/2022/May/35](http://seclists.org/fulldisclosure/2022/May/35)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/) -
Haute CVE-2022-29404 Signalée 09/06/2022In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.
* [http://www.openwall.com/lists/oss-security/2022/06/08/5](http://www.openwall.com/lists/oss-security/2022/06/08/5)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://security.netapp.com/advisory/ntap-20220624-0005/](https://security.netapp.com/advisory/ntap-20220624-0005/)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/) -
Haute CVE-2022-30556 Signalée 09/06/2022Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
* [http://www.openwall.com/lists/oss-security/2022/06/08/7](http://www.openwall.com/lists/oss-security/2022/06/08/7)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://security.netapp.com/advisory/ntap-20220624-0005/](https://security.netapp.com/advisory/ntap-20220624-0005/)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/) -
Haute CVE-2023-31122 Signalée 23/10/2023Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TI3V2YCEUM65QDYPGGNUZ7UONIM5OEXC/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TI3V2YCEUM65QDYPGGNUZ7UONIM5OEXC/)
* [https://security.netapp.com/advisory/ntap-20231027-0011/](https://security.netapp.com/advisory/ntap-20231027-0011/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZJTT5TEFNSBWVMKCLS6EZ7PI6EJYBCO/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VZJTT5TEFNSBWVMKCLS6EZ7PI6EJYBCO/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZFDNHDH4VLFGDPY6MEZV2RO5N5FLFONW/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZFDNHDH4VLFGDPY6MEZV2RO5N5FLFONW/)
* [https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html](https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html) -
Haute CVE-2024-40898 Signalée 18/07/2024SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
-
Haute CVE-2025-58098 Signalée 05/12/2025Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.
* [http://www.openwall.com/lists/oss-security/2025/12/04/5](http://www.openwall.com/lists/oss-security/2025/12/04/5)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Haute CVE-2026-24072 Signalée 04/05/2026An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
* [http://www.openwall.com/lists/oss-security/2026/05/04/18](http://www.openwall.com/lists/oss-security/2026/05/04/18)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Haute CVE-2026-29169 Signalée 04/05/2026A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
* [http://www.openwall.com/lists/oss-security/2026/05/04/20](http://www.openwall.com/lists/oss-security/2026/05/04/20)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Haute CVE-2026-34059 Signalée 04/05/2026Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
* [http://www.openwall.com/lists/oss-security/2026/05/04/17](http://www.openwall.com/lists/oss-security/2026/05/04/17)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Moyenne CVE-2005-3352 Signalée 13/12/2005Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
* [http://securitytracker.com/id?1015344](http://securitytracker.com/id?1015344)
* [http://www.securityfocus.com/bid/15834](http://www.securityfocus.com/bid/15834)
* [http://secunia.com/advisories/18008](http://secunia.com/advisories/18008)
* [http://issues.apache.org/bugzilla/show_bug.cgi?id=37874](http://issues.apache.org/bugzilla/show_bug.cgi?id=37874)
* [http://www.openpkg.org/security/OpenPKG-SA-2005.029-apache.txt](http://www.openpkg.org/security/OpenPKG-SA-2005.029-apache.txt)
* [http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007](http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007)
* [http://rhn.redhat.com/errata/RHSA-2006-0159.html](http://rhn.redhat.com/errata/RHSA-2006-0159.html)
* [http://www.trustix.org/errata/2005/0074/](http://www.trustix.org/errata/2005/0074/)
* [http://secunia.com/advisories/18333](http://secunia.com/advisories/18333)
* [http://secunia.com/advisories/18339](http://secunia.com/advisories/18339)
* [http://secunia.com/advisories/18340](http://secunia.com/advisories/18340)
* [http://www.ubuntulinux.org/usn/usn-241-1](http://www.ubuntulinux.org/usn/usn-241-1)
* [http://secunia.com/advisories/18429](http://secunia.com/advisories/18429)
* [http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.html](http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.html)
* [http://secunia.com/advisories/18585](http://secunia.com/advisories/18585)
* [ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U](ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U)
* [http://secunia.com/advisories/18517](http://secunia.com/advisories/18517)
* [http://www.gentoo.org/security/en/glsa/glsa-200602-03.xml](http://www.gentoo.org/security/en/glsa/glsa-200602-03.xml)
* [http://secunia.com/advisories/18743](http://secunia.com/advisories/18743)
* [http://www.redhat.com/support/errata/RHSA-2006-0158.html](http://www.redhat.com/support/errata/RHSA-2006-0158.html)
* [http://secunia.com/advisories/17319](http://secunia.com/advisories/17319)
* [http://www-1.ibm.com/support/search.wss?rs=0&q=PK16139&apar=only](http://www-1.ibm.com/support/search.wss?rs=0&q=PK16139&apar=only)
* [http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html](http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html)
* [http://secunia.com/advisories/18526](http://secunia.com/advisories/18526)
* [http://secunia.com/advisories/19012](http://secunia.com/advisories/19012)
* [http://www-1.ibm.com/support/search.wss?rs=0&q=PK25355&apar=only](http://www-1.ibm.com/support/search.wss?rs=0&q=PK25355&apar=only)
* [http://secunia.com/advisories/20670](http://secunia.com/advisories/20670)
* [http://www.novell.com/linux/security/advisories/2006_43_apache.html](http://www.novell.com/linux/security/advisories/2006_43_apache.html)
* [http://www.debian.org/security/2006/dsa-1167](http://www.debian.org/security/2006/dsa-1167)
* [http://secunia.com/advisories/21744](http://secunia.com/advisories/21744)
* [http://rhn.redhat.com/errata/RHSA-2006-0692.html](http://rhn.redhat.com/errata/RHSA-2006-0692.html)
* [http://secunia.com/advisories/22140](http://secunia.com/advisories/22140)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1)
* [http://secunia.com/advisories/22368](http://secunia.com/advisories/22368)
* [http://secunia.com/advisories/22388](http://secunia.com/advisories/22388)
* [http://secunia.com/advisories/22669](http://secunia.com/advisories/22669)
* [http://secunia.com/advisories/23260](http://secunia.com/advisories/23260)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.685483](http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.685483)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.470158](http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.470158)
* [http://secunia.com/advisories/20046](http://secunia.com/advisories/20046)
* [http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html](http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html)
* [http://secunia.com/advisories/25239](http://secunia.com/advisories/25239)
* [http://docs.info.apple.com/article.html?artnum=307562](http://docs.info.apple.com/article.html?artnum=307562)
* [http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html](http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html)
* [http://secunia.com/advisories/29420](http://secunia.com/advisories/29420)
* [http://secunia.com/advisories/29849](http://secunia.com/advisories/29849)
* [http://lists.apple.com/archives/security-announce/2008//May/msg00001.html](http://lists.apple.com/archives/security-announce/2008//May/msg00001.html)
* [http://www.us-cert.gov/cas/techalerts/TA08-150A.html](http://www.us-cert.gov/cas/techalerts/TA08-150A.html)
* [http://secunia.com/advisories/30430](http://secunia.com/advisories/30430)
* [http://www.vupen.com/english/advisories/2006/3995](http://www.vupen.com/english/advisories/2006/3995)
* [http://www.vupen.com/english/advisories/2006/4300](http://www.vupen.com/english/advisories/2006/4300)
* [http://www.vupen.com/english/advisories/2008/1697](http://www.vupen.com/english/advisories/2008/1697)
* [http://www.vupen.com/english/advisories/2008/0924/references](http://www.vupen.com/english/advisories/2008/0924/references)
* [http://www.vupen.com/english/advisories/2006/2423](http://www.vupen.com/english/advisories/2006/2423)
* [http://www.vupen.com/english/advisories/2006/4015](http://www.vupen.com/english/advisories/2006/4015)
* [http://www.vupen.com/english/advisories/2005/2870](http://www.vupen.com/english/advisories/2005/2870)
* [http://www.vupen.com/english/advisories/2008/1246/references](http://www.vupen.com/english/advisories/2008/1246/references)
* [http://www.vupen.com/english/advisories/2006/4868](http://www.vupen.com/english/advisories/2006/4868)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449)
* [http://marc.info/?l=bugtraq&m=130497311408250&w=2](http://marc.info/?l=bugtraq&m=130497311408250&w=2)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10480](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10480)
* [http://www.securityfocus.com/archive/1/450321/100/0/threaded](http://www.securityfocus.com/archive/1/450321/100/0/threaded)
* [http://www.securityfocus.com/archive/1/450315/100/0/threaded](http://www.securityfocus.com/archive/1/450315/100/0/threaded)
* [http://www.securityfocus.com/archive/1/445206/100/0/threaded](http://www.securityfocus.com/archive/1/445206/100/0/threaded)
* [http://www.securityfocus.com/archive/1/425399/100/0/threaded](http://www.securityfocus.com/archive/1/425399/100/0/threaded)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2006-4154 Signalée 16/10/2006Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c.
* [http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=421](http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=421)
* [http://www.securityfocus.com/bid/20527](http://www.securityfocus.com/bid/20527)
* [http://securitytracker.com/id?1017062](http://securitytracker.com/id?1017062)
* [http://secunia.com/advisories/22458](http://secunia.com/advisories/22458)
* [http://www.osvdb.org/29536](http://www.osvdb.org/29536)
* [http://security.gentoo.org/glsa/glsa-200610-12.xml](http://security.gentoo.org/glsa/glsa-200610-12.xml)
* [http://secunia.com/advisories/22549](http://secunia.com/advisories/22549)
* [http://www.kb.cert.org/vuls/id/366020](http://www.kb.cert.org/vuls/id/366020)
* [http://www.vupen.com/english/advisories/2006/4033](http://www.vupen.com/english/advisories/2006/4033)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/29550](https://exchange.xforce.ibmcloud.com/vulnerabilities/29550) -
Moyenne CVE-2006-5752 Signalée 27/06/2007Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
* [http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=245112](http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=245112)
* [http://svn.apache.org/viewvc?view=rev&revision=549159](http://svn.apache.org/viewvc?view=rev&revision=549159)
* [http://www.redhat.com/support/errata/RHSA-2007-0532.html](http://www.redhat.com/support/errata/RHSA-2007-0532.html)
* [http://rhn.redhat.com/errata/RHSA-2007-0534.html](http://rhn.redhat.com/errata/RHSA-2007-0534.html)
* [http://rhn.redhat.com/errata/RHSA-2007-0556.html](http://rhn.redhat.com/errata/RHSA-2007-0556.html)
* [http://www.securityfocus.com/bid/24645](http://www.securityfocus.com/bid/24645)
* [https://issues.rpath.com/browse/RPL-1500](https://issues.rpath.com/browse/RPL-1500)
* [http://httpd.apache.org/security/vulnerabilities_13.html](http://httpd.apache.org/security/vulnerabilities_13.html)
* [http://httpd.apache.org/security/vulnerabilities_20.html](http://httpd.apache.org/security/vulnerabilities_20.html)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm](http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm)
* [http://bugs.gentoo.org/show_bug.cgi?id=186219](http://bugs.gentoo.org/show_bug.cgi?id=186219)
* [http://www-1.ibm.com/support/search.wss?rs=0&q=PK49295&apar=only](http://www-1.ibm.com/support/search.wss?rs=0&q=PK49295&apar=only)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702](http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702)
* [http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html](http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html)
* [http://security.gentoo.org/glsa/glsa-200711-06.xml](http://security.gentoo.org/glsa/glsa-200711-06.xml)
* [http://www.mandriva.com/security/advisories?name=MDKSA-2007:140](http://www.mandriva.com/security/advisories?name=MDKSA-2007:140)
* [http://www.mandriva.com/security/advisories?name=MDKSA-2007:141](http://www.mandriva.com/security/advisories?name=MDKSA-2007:141)
* [http://www.mandriva.com/security/advisories?name=MDKSA-2007:142](http://www.mandriva.com/security/advisories?name=MDKSA-2007:142)
* [https://rhn.redhat.com/errata/RHSA-2007-0533.html](https://rhn.redhat.com/errata/RHSA-2007-0533.html)
* [http://www.redhat.com/support/errata/RHSA-2007-0557.html](http://www.redhat.com/support/errata/RHSA-2007-0557.html)
* [http://www.novell.com/linux/security/advisories/2007_61_apache2.html](http://www.novell.com/linux/security/advisories/2007_61_apache2.html)
* [http://www.trustix.org/errata/2007/0026/](http://www.trustix.org/errata/2007/0026/)
* [http://www.ubuntu.com/usn/usn-499-1](http://www.ubuntu.com/usn/usn-499-1)
* [http://www.securitytracker.com/id?1018302](http://www.securitytracker.com/id?1018302)
* [http://secunia.com/advisories/25827](http://secunia.com/advisories/25827)
* [http://secunia.com/advisories/25830](http://secunia.com/advisories/25830)
* [http://secunia.com/advisories/25873](http://secunia.com/advisories/25873)
* [http://secunia.com/advisories/25920](http://secunia.com/advisories/25920)
* [http://secunia.com/advisories/26273](http://secunia.com/advisories/26273)
* [http://secunia.com/advisories/26443](http://secunia.com/advisories/26443)
* [http://secunia.com/advisories/26458](http://secunia.com/advisories/26458)
* [http://secunia.com/advisories/26508](http://secunia.com/advisories/26508)
* [http://secunia.com/advisories/26822](http://secunia.com/advisories/26822)
* [http://secunia.com/advisories/26842](http://secunia.com/advisories/26842)
* [http://secunia.com/advisories/26993](http://secunia.com/advisories/26993)
* [http://secunia.com/advisories/27037](http://secunia.com/advisories/27037)
* [http://secunia.com/advisories/27563](http://secunia.com/advisories/27563)
* [http://secunia.com/advisories/27732](http://secunia.com/advisories/27732)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-103179-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-103179-1)
* [http://secunia.com/advisories/28212](http://secunia.com/advisories/28212)
* [http://secunia.com/advisories/28224](http://secunia.com/advisories/28224)
* [http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html](http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html)
* [http://secunia.com/advisories/28606](http://secunia.com/advisories/28606)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-66-200032-1](http://sunsolve.sun.com/search/document.do?assetkey=1-66-200032-1)
* [http://www.redhat.com/support/errata/RHSA-2008-0261.html](http://www.redhat.com/support/errata/RHSA-2008-0261.html)
* [http://lists.vmware.com/pipermail/security-announce/2009/000062.html](http://lists.vmware.com/pipermail/security-announce/2009/000062.html)
* [http://www.vupen.com/english/advisories/2008/0233](http://www.vupen.com/english/advisories/2008/0233)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795)
* [http://www.vupen.com/english/advisories/2007/4305](http://www.vupen.com/english/advisories/2007/4305)
* [http://www.vupen.com/english/advisories/2007/2727](http://www.vupen.com/english/advisories/2007/2727)
* [http://www.vupen.com/english/advisories/2007/3283](http://www.vupen.com/english/advisories/2007/3283)
* [http://www.vupen.com/english/advisories/2007/3386](http://www.vupen.com/english/advisories/2007/3386)
* [http://osvdb.org/37052](http://osvdb.org/37052)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/35097](https://exchange.xforce.ibmcloud.com/vulnerabilities/35097)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10154](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10154)
* [http://www.securityfocus.com/archive/1/505990/100/0/threaded](http://www.securityfocus.com/archive/1/505990/100/0/threaded)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2007-1863 Signalée 27/06/2007cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
* [http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244658](http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244658)
* [http://svn.apache.org/viewvc?view=rev&revision=535617](http://svn.apache.org/viewvc?view=rev&revision=535617)
* [http://rhn.redhat.com/errata/RHSA-2007-0534.html](http://rhn.redhat.com/errata/RHSA-2007-0534.html)
* [http://rhn.redhat.com/errata/RHSA-2007-0556.html](http://rhn.redhat.com/errata/RHSA-2007-0556.html)
* [http://www.securityfocus.com/bid/24649](http://www.securityfocus.com/bid/24649)
* [https://issues.rpath.com/browse/RPL-1500](https://issues.rpath.com/browse/RPL-1500)
* [http://httpd.apache.org/security/vulnerabilities_20.html](http://httpd.apache.org/security/vulnerabilities_20.html)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm](http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm)
* [http://bugs.gentoo.org/show_bug.cgi?id=186219](http://bugs.gentoo.org/show_bug.cgi?id=186219)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK49355](http://www-1.ibm.com/support/docview.wss?uid=swg1PK49355)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702](http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702)
* [http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html](http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html)
* [http://security.gentoo.org/glsa/glsa-200711-06.xml](http://security.gentoo.org/glsa/glsa-200711-06.xml)
* [http://www.mandriva.com/security/advisories?name=MDKSA-2007:140](http://www.mandriva.com/security/advisories?name=MDKSA-2007:140)
* [http://www.mandriva.com/security/advisories?name=MDKSA-2007:141](http://www.mandriva.com/security/advisories?name=MDKSA-2007:141)
* [https://rhn.redhat.com/errata/RHSA-2007-0533.html](https://rhn.redhat.com/errata/RHSA-2007-0533.html)
* [http://www.redhat.com/support/errata/RHSA-2007-0557.html](http://www.redhat.com/support/errata/RHSA-2007-0557.html)
* [http://www.novell.com/linux/security/advisories/2007_61_apache2.html](http://www.novell.com/linux/security/advisories/2007_61_apache2.html)
* [http://www.trustix.org/errata/2007/0026/](http://www.trustix.org/errata/2007/0026/)
* [http://www.ubuntu.com/usn/usn-499-1](http://www.ubuntu.com/usn/usn-499-1)
* [http://www.securitytracker.com/id?1018303](http://www.securitytracker.com/id?1018303)
* [http://secunia.com/advisories/25830](http://secunia.com/advisories/25830)
* [http://secunia.com/advisories/25873](http://secunia.com/advisories/25873)
* [http://secunia.com/advisories/25920](http://secunia.com/advisories/25920)
* [http://secunia.com/advisories/26273](http://secunia.com/advisories/26273)
* [http://secunia.com/advisories/26443](http://secunia.com/advisories/26443)
* [http://secunia.com/advisories/26508](http://secunia.com/advisories/26508)
* [http://secunia.com/advisories/26822](http://secunia.com/advisories/26822)
* [http://secunia.com/advisories/26842](http://secunia.com/advisories/26842)
* [http://secunia.com/advisories/26993](http://secunia.com/advisories/26993)
* [http://secunia.com/advisories/27037](http://secunia.com/advisories/27037)
* [http://secunia.com/advisories/27563](http://secunia.com/advisories/27563)
* [http://secunia.com/advisories/27732](http://secunia.com/advisories/27732)
* [http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html](http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html)
* [http://secunia.com/advisories/28606](http://secunia.com/advisories/28606)
* [http://lists.apple.com/archives/security-announce/2008//May/msg00001.html](http://lists.apple.com/archives/security-announce/2008//May/msg00001.html)
* [http://www.us-cert.gov/cas/techalerts/TA08-150A.html](http://www.us-cert.gov/cas/techalerts/TA08-150A.html)
* [http://secunia.com/advisories/30430](http://secunia.com/advisories/30430)
* [http://lists.vmware.com/pipermail/security-announce/2009/000062.html](http://lists.vmware.com/pipermail/security-announce/2009/000062.html)
* [http://www.vupen.com/english/advisories/2008/0233](http://www.vupen.com/english/advisories/2008/0233)
* [http://www.vupen.com/english/advisories/2008/1697](http://www.vupen.com/english/advisories/2008/1697)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795)
* [http://www.vupen.com/english/advisories/2007/2727](http://www.vupen.com/english/advisories/2007/2727)
* [http://www.vupen.com/english/advisories/2007/3283](http://www.vupen.com/english/advisories/2007/3283)
* [http://www.vupen.com/english/advisories/2007/3386](http://www.vupen.com/english/advisories/2007/3386)
* [http://osvdb.org/37079](http://osvdb.org/37079)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9824](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9824)
* [http://www.securityfocus.com/archive/1/505990/100/0/threaded](http://www.securityfocus.com/archive/1/505990/100/0/threaded)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2007-3304 Signalée 20/06/2007Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
* [http://security.psnc.pl/files/apache_report.pdf](http://security.psnc.pl/files/apache_report.pdf)
* [http://marc.info/?l=apache-httpd-dev&m=118252946632447&w=2](http://marc.info/?l=apache-httpd-dev&m=118252946632447&w=2)
* [http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=245111](http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=245111)
* [http://svn.apache.org/viewvc?view=rev&revision=547987](http://svn.apache.org/viewvc?view=rev&revision=547987)
* [http://httpd.apache.org/security/vulnerabilities_13.html](http://httpd.apache.org/security/vulnerabilities_13.html)
* [http://httpd.apache.org/security/vulnerabilities_20.html](http://httpd.apache.org/security/vulnerabilities_20.html)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm](http://support.avaya.com/elmodocs2/security/ASA-2007-353.htm)
* [http://support.avaya.com/elmodocs2/security/ASA-2007-363.htm](http://support.avaya.com/elmodocs2/security/ASA-2007-363.htm)
* [https://issues.rpath.com/browse/RPL-1710](https://issues.rpath.com/browse/RPL-1710)
* [http://bugs.gentoo.org/show_bug.cgi?id=186219](http://bugs.gentoo.org/show_bug.cgi?id=186219)
* [http://www-1.ibm.com/support/search.wss?rs=0&q=PK50467&apar=only](http://www-1.ibm.com/support/search.wss?rs=0&q=PK50467&apar=only)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702](http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK53984](http://www-1.ibm.com/support/docview.wss?uid=swg1PK53984)
* [http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html](http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html)
* [http://security.gentoo.org/glsa/glsa-200711-06.xml](http://security.gentoo.org/glsa/glsa-200711-06.xml)
* [http://www.mandriva.com/security/advisories?name=MDKSA-2007:140](http://www.mandriva.com/security/advisories?name=MDKSA-2007:140)
* [http://www.mandriva.com/security/advisories?name=MDKSA-2007:142](http://www.mandriva.com/security/advisories?name=MDKSA-2007:142)
* [http://www.redhat.com/errata/RHSA-2007-0532.html](http://www.redhat.com/errata/RHSA-2007-0532.html)
* [http://rhn.redhat.com/errata/RHSA-2007-0556.html](http://rhn.redhat.com/errata/RHSA-2007-0556.html)
* [http://www.redhat.com/support/errata/RHSA-2007-0557.html](http://www.redhat.com/support/errata/RHSA-2007-0557.html)
* [http://www.redhat.com/support/errata/RHSA-2007-0662.html](http://www.redhat.com/support/errata/RHSA-2007-0662.html)
* [ftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.asc](ftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.asc)
* [http://www.novell.com/linux/security/advisories/2007_61_apache2.html](http://www.novell.com/linux/security/advisories/2007_61_apache2.html)
* [http://www.trustix.org/errata/2007/0026/](http://www.trustix.org/errata/2007/0026/)
* [http://www.ubuntu.com/usn/usn-499-1](http://www.ubuntu.com/usn/usn-499-1)
* [http://www.securityfocus.com/bid/24215](http://www.securityfocus.com/bid/24215)
* [http://www.securitytracker.com/id?1018304](http://www.securitytracker.com/id?1018304)
* [http://secunia.com/advisories/25827](http://secunia.com/advisories/25827)
* [http://secunia.com/advisories/25830](http://secunia.com/advisories/25830)
* [http://secunia.com/advisories/25920](http://secunia.com/advisories/25920)
* [http://secunia.com/advisories/26211](http://secunia.com/advisories/26211)
* [http://secunia.com/advisories/26273](http://secunia.com/advisories/26273)
* [http://secunia.com/advisories/26443](http://secunia.com/advisories/26443)
* [http://secunia.com/advisories/26508](http://secunia.com/advisories/26508)
* [http://secunia.com/advisories/26611](http://secunia.com/advisories/26611)
* [http://secunia.com/advisories/26759](http://secunia.com/advisories/26759)
* [http://secunia.com/advisories/26790](http://secunia.com/advisories/26790)
* [http://secunia.com/advisories/26822](http://secunia.com/advisories/26822)
* [http://secunia.com/advisories/26842](http://secunia.com/advisories/26842)
* [http://secunia.com/advisories/26993](http://secunia.com/advisories/26993)
* [http://secunia.com/advisories/27121](http://secunia.com/advisories/27121)
* [http://secunia.com/advisories/27209](http://secunia.com/advisories/27209)
* [http://secunia.com/advisories/27563](http://secunia.com/advisories/27563)
* [http://secunia.com/advisories/27732](http://secunia.com/advisories/27732)
* [http://securityreason.com/securityalert/2814](http://securityreason.com/securityalert/2814)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-103179-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-103179-1)
* [http://secunia.com/advisories/28212](http://secunia.com/advisories/28212)
* [http://secunia.com/advisories/28224](http://secunia.com/advisories/28224)
* [http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html](http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html)
* [http://secunia.com/advisories/28606](http://secunia.com/advisories/28606)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-66-200032-1](http://sunsolve.sun.com/search/document.do?assetkey=1-66-200032-1)
* [http://www.redhat.com/support/errata/RHSA-2008-0261.html](http://www.redhat.com/support/errata/RHSA-2008-0261.html)
* [http://lists.vmware.com/pipermail/security-announce/2009/000062.html](http://lists.vmware.com/pipermail/security-announce/2009/000062.html)
* [http://www.vupen.com/english/advisories/2008/0233](http://www.vupen.com/english/advisories/2008/0233)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01182588](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01182588)
* [http://www.vupen.com/english/advisories/2007/3494](http://www.vupen.com/english/advisories/2007/3494)
* [http://www.vupen.com/english/advisories/2007/3100](http://www.vupen.com/english/advisories/2007/3100)
* [http://www.vupen.com/english/advisories/2007/3420](http://www.vupen.com/english/advisories/2007/3420)
* [http://www.vupen.com/english/advisories/2007/4305](http://www.vupen.com/english/advisories/2007/4305)
* [http://www.vupen.com/english/advisories/2007/3283](http://www.vupen.com/english/advisories/2007/3283)
* [http://www.vupen.com/english/advisories/2007/2727](http://www.vupen.com/english/advisories/2007/2727)
* [http://osvdb.org/38939](http://osvdb.org/38939)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/35095](https://exchange.xforce.ibmcloud.com/vulnerabilities/35095)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11589](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11589)
* [http://www.securityfocus.com/archive/1/505990/100/0/threaded](http://www.securityfocus.com/archive/1/505990/100/0/threaded)
* [http://www.securityfocus.com/archive/1/471832/100/0/threaded](http://www.securityfocus.com/archive/1/471832/100/0/threaded)
* [http://www.securityfocus.com/archive/1/469899/100/0/threaded](http://www.securityfocus.com/archive/1/469899/100/0/threaded)
* [http://mail-archives.apache.org/mod_mbox/httpd-dev/200706.mbox/%3c20070629141032.GA15192%40redhat.com%3e](http://mail-archives.apache.org/mod_mbox/httpd-dev/200706.mbox/%3c20070629141032.GA15192%40redhat.com%3e)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2007-3847 Signalée 23/08/2007The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
* [http://marc.info/?l=apache-cvs&m=118592992309395&w=2](http://marc.info/?l=apache-cvs&m=118592992309395&w=2)
* [http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2](http://marc.info/?l=apache-httpd-dev&m=118595556504202&w=2)
* [http://marc.info/?l=apache-httpd-dev&m=118595953217856&w=2](http://marc.info/?l=apache-httpd-dev&m=118595953217856&w=2)
* [http://httpd.apache.org/security/vulnerabilities_20.html](http://httpd.apache.org/security/vulnerabilities_20.html)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [https://issues.rpath.com/browse/RPL-1710](https://issues.rpath.com/browse/RPL-1710)
* [http://bugs.gentoo.org/show_bug.cgi?id=186219](http://bugs.gentoo.org/show_bug.cgi?id=186219)
* [http://support.avaya.com/elmodocs2/security/ASA-2007-500.htm](http://support.avaya.com/elmodocs2/security/ASA-2007-500.htm)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK50469](http://www-1.ibm.com/support/docview.wss?uid=swg1PK50469)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702](http://www-1.ibm.com/support/docview.wss?uid=swg1PK52702)
* [http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html](http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html)
* [https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00353.html](https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00353.html)
* [http://security.gentoo.org/glsa/glsa-200711-06.xml](http://security.gentoo.org/glsa/glsa-200711-06.xml)
* [http://www.mandriva.com/security/advisories?name=MDKSA-2007:235](http://www.mandriva.com/security/advisories?name=MDKSA-2007:235)
* [http://www.redhat.com/support/errata/RHSA-2007-0911.html](http://www.redhat.com/support/errata/RHSA-2007-0911.html)
* [http://www.redhat.com/support/errata/RHSA-2007-0746.html](http://www.redhat.com/support/errata/RHSA-2007-0746.html)
* [http://www.redhat.com/support/errata/RHSA-2007-0747.html](http://www.redhat.com/support/errata/RHSA-2007-0747.html)
* [http://www.novell.com/linux/security/advisories/2007_61_apache2.html](http://www.novell.com/linux/security/advisories/2007_61_apache2.html)
* [http://www.securityfocus.com/bid/25489](http://www.securityfocus.com/bid/25489)
* [http://www.securitytracker.com/id?1018633](http://www.securitytracker.com/id?1018633)
* [http://secunia.com/advisories/26636](http://secunia.com/advisories/26636)
* [http://secunia.com/advisories/26722](http://secunia.com/advisories/26722)
* [http://secunia.com/advisories/26790](http://secunia.com/advisories/26790)
* [http://secunia.com/advisories/26842](http://secunia.com/advisories/26842)
* [http://secunia.com/advisories/26952](http://secunia.com/advisories/26952)
* [http://secunia.com/advisories/26993](http://secunia.com/advisories/26993)
* [http://secunia.com/advisories/27209](http://secunia.com/advisories/27209)
* [http://secunia.com/advisories/27563](http://secunia.com/advisories/27563)
* [http://secunia.com/advisories/27593](http://secunia.com/advisories/27593)
* [http://secunia.com/advisories/27732](http://secunia.com/advisories/27732)
* [http://secunia.com/advisories/27882](http://secunia.com/advisories/27882)
* [http://secunia.com/advisories/27971](http://secunia.com/advisories/27971)
* [http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27007951](http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg27007951)
* [http://www.redhat.com/support/errata/RHSA-2008-0005.html](http://www.redhat.com/support/errata/RHSA-2008-0005.html)
* [http://secunia.com/advisories/28467](http://secunia.com/advisories/28467)
* [http://www.ubuntu.com/usn/usn-575-1](http://www.ubuntu.com/usn/usn-575-1)
* [http://secunia.com/advisories/28749](http://secunia.com/advisories/28749)
* [http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html](http://www.fujitsu.com/global/support/software/security/products-f/interstage-200802e.html)
* [http://secunia.com/advisories/28606](http://secunia.com/advisories/28606)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748](http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748)
* [http://secunia.com/advisories/28922](http://secunia.com/advisories/28922)
* [http://docs.info.apple.com/article.html?artnum=307562](http://docs.info.apple.com/article.html?artnum=307562)
* [http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html](http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html)
* [http://secunia.com/advisories/29420](http://secunia.com/advisories/29420)
* [http://lists.apple.com/archives/security-announce/2008//May/msg00001.html](http://lists.apple.com/archives/security-announce/2008//May/msg00001.html)
* [http://www.us-cert.gov/cas/techalerts/TA08-150A.html](http://www.us-cert.gov/cas/techalerts/TA08-150A.html)
* [http://secunia.com/advisories/30430](http://secunia.com/advisories/30430)
* [http://lists.vmware.com/pipermail/security-announce/2009/000062.html](http://lists.vmware.com/pipermail/security-announce/2009/000062.html)
* [http://www.vupen.com/english/advisories/2008/0233](http://www.vupen.com/english/advisories/2008/0233)
* [http://www.vupen.com/english/advisories/2008/1697](http://www.vupen.com/english/advisories/2008/1697)
* [http://www.vupen.com/english/advisories/2007/3494](http://www.vupen.com/english/advisories/2007/3494)
* [http://www.vupen.com/english/advisories/2007/3020](http://www.vupen.com/english/advisories/2007/3020)
* [http://www.vupen.com/english/advisories/2008/0924/references](http://www.vupen.com/english/advisories/2008/0924/references)
* [http://www.vupen.com/english/advisories/2007/3955](http://www.vupen.com/english/advisories/2007/3955)
* [http://www.vupen.com/english/advisories/2007/3095](http://www.vupen.com/english/advisories/2007/3095)
* [http://www.vupen.com/english/advisories/2007/3283](http://www.vupen.com/english/advisories/2007/3283)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01182588](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01182588)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10525](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10525)
* [http://www.securityfocus.com/archive/1/505990/100/0/threaded](http://www.securityfocus.com/archive/1/505990/100/0/threaded)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2007-4465 Signalée 14/09/2007Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
* [http://securityreason.com/achievement_securityalert/46](http://securityreason.com/achievement_securityalert/46)
* [http://www.apache.org/dist/httpd/CHANGES_2.2.6](http://www.apache.org/dist/httpd/CHANGES_2.2.6)
* [http://www.securityfocus.com/bid/25653](http://www.securityfocus.com/bid/25653)
* [http://securityreason.com/securityalert/3113](http://securityreason.com/securityalert/3113)
* [http://bugs.gentoo.org/show_bug.cgi?id=186219](http://bugs.gentoo.org/show_bug.cgi?id=186219)
* [http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html](http://www.redhat.com/archives/fedora-package-announce/2007-September/msg00320.html)
* [https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00353.html](https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00353.html)
* [http://security.gentoo.org/glsa/glsa-200711-06.xml](http://security.gentoo.org/glsa/glsa-200711-06.xml)
* [http://www.redhat.com/support/errata/RHSA-2007-0911.html](http://www.redhat.com/support/errata/RHSA-2007-0911.html)
* [http://www.novell.com/linux/security/advisories/2007_61_apache2.html](http://www.novell.com/linux/security/advisories/2007_61_apache2.html)
* [http://secunia.com/advisories/26842](http://secunia.com/advisories/26842)
* [http://secunia.com/advisories/26952](http://secunia.com/advisories/26952)
* [http://secunia.com/advisories/27563](http://secunia.com/advisories/27563)
* [http://secunia.com/advisories/27732](http://secunia.com/advisories/27732)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:014](http://www.mandriva.com/security/advisories?name=MDVSA-2008:014)
* [http://www.redhat.com/support/errata/RHSA-2008-0004.html](http://www.redhat.com/support/errata/RHSA-2008-0004.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0005.html](http://www.redhat.com/support/errata/RHSA-2008-0005.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0006.html](http://www.redhat.com/support/errata/RHSA-2008-0006.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0008.html](http://www.redhat.com/support/errata/RHSA-2008-0008.html)
* [http://securitytracker.com/id?1019194](http://securitytracker.com/id?1019194)
* [http://secunia.com/advisories/28467](http://secunia.com/advisories/28467)
* [http://secunia.com/advisories/28471](http://secunia.com/advisories/28471)
* [http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm](http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm)
* [http://secunia.com/advisories/28607](http://secunia.com/advisories/28607)
* [http://www.ubuntu.com/usn/usn-575-1](http://www.ubuntu.com/usn/usn-575-1)
* [http://secunia.com/advisories/28749](http://secunia.com/advisories/28749)
* [http://www.redhat.com/support/errata/RHSA-2008-0261.html](http://www.redhat.com/support/errata/RHSA-2008-0261.html)
* [http://lists.apple.com/archives/security-announce/2008//May/msg00001.html](http://lists.apple.com/archives/security-announce/2008//May/msg00001.html)
* [http://www.us-cert.gov/cas/techalerts/TA08-150A.html](http://www.us-cert.gov/cas/techalerts/TA08-150A.html)
* [http://secunia.com/advisories/30430](http://secunia.com/advisories/30430)
* [http://secunia.com/advisories/31651](http://secunia.com/advisories/31651)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432)
* [http://secunia.com/advisories/33105](http://secunia.com/advisories/33105)
* [http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html](http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html)
* [http://secunia.com/advisories/35650](http://secunia.com/advisories/35650)
* [http://marc.info/?l=bugtraq&m=124654546101607&w=2](http://marc.info/?l=bugtraq&m=124654546101607&w=2)
* [http://marc.info/?l=bugtraq&m=125631037611762&w=2](http://marc.info/?l=bugtraq&m=125631037611762&w=2)
* [http://www.vupen.com/english/advisories/2008/1697](http://www.vupen.com/english/advisories/2008/1697)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/36586](https://exchange.xforce.ibmcloud.com/vulnerabilities/36586)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6089](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6089)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10929](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10929)
* [http://www.securityfocus.com/archive/1/479237/100/0/threaded](http://www.securityfocus.com/archive/1/479237/100/0/threaded) -
Moyenne CVE-2007-5000 Signalée 13/12/2007Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
* [http://httpd.apache.org/security/vulnerabilities_13.html](http://httpd.apache.org/security/vulnerabilities_13.html)
* [http://httpd.apache.org/security/vulnerabilities_20.html](http://httpd.apache.org/security/vulnerabilities_20.html)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://secunia.com/advisories/28046](http://secunia.com/advisories/28046)
* [http://secunia.com/advisories/28073](http://secunia.com/advisories/28073)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK58024](http://www-1.ibm.com/support/docview.wss?uid=swg1PK58024)
* [http://www.securityfocus.com/bid/26838](http://www.securityfocus.com/bid/26838)
* [http://securitytracker.com/id?1019093](http://securitytracker.com/id?1019093)
* [http://secunia.com/advisories/28081](http://secunia.com/advisories/28081)
* [http://secunia.com/advisories/28196](http://secunia.com/advisories/28196)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK58074](http://www-1.ibm.com/support/docview.wss?uid=swg1PK58074)
* [http://secunia.com/advisories/28375](http://secunia.com/advisories/28375)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:014](http://www.mandriva.com/security/advisories?name=MDVSA-2008:014)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:015](http://www.mandriva.com/security/advisories?name=MDVSA-2008:015)
* [http://www.redhat.com/support/errata/RHSA-2008-0004.html](http://www.redhat.com/support/errata/RHSA-2008-0004.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0005.html](http://www.redhat.com/support/errata/RHSA-2008-0005.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0006.html](http://www.redhat.com/support/errata/RHSA-2008-0006.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0007.html](http://www.redhat.com/support/errata/RHSA-2008-0007.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0008.html](http://www.redhat.com/support/errata/RHSA-2008-0008.html)
* [http://secunia.com/advisories/28467](http://secunia.com/advisories/28467)
* [http://secunia.com/advisories/28471](http://secunia.com/advisories/28471)
* [http://www.fujitsu.com/global/support/software/security/products-f/interstage-200801e.html](http://www.fujitsu.com/global/support/software/security/products-f/interstage-200801e.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:016](http://www.mandriva.com/security/advisories?name=MDVSA-2008:016)
* [http://secunia.com/advisories/28525](http://secunia.com/advisories/28525)
* [http://secunia.com/advisories/28526](http://secunia.com/advisories/28526)
* [http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm](http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm)
* [http://secunia.com/advisories/28607](http://secunia.com/advisories/28607)
* [http://www.ubuntu.com/usn/usn-575-1](http://www.ubuntu.com/usn/usn-575-1)
* [http://secunia.com/advisories/28749](http://secunia.com/advisories/28749)
* [http://secunia.com/advisories/28750](http://secunia.com/advisories/28750)
* [http://www.osvdb.org/39134](http://www.osvdb.org/39134)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748](http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748)
* [http://secunia.com/advisories/28977](http://secunia.com/advisories/28977)
* [http://secunia.com/advisories/28922](http://secunia.com/advisories/28922)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-233623-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-233623-1)
* [http://docs.info.apple.com/article.html?artnum=307562](http://docs.info.apple.com/article.html?artnum=307562)
* [http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html](http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html)
* [http://secunia.com/advisories/29420](http://secunia.com/advisories/29420)
* [http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html](http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html)
* [http://secunia.com/advisories/29640](http://secunia.com/advisories/29640)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK63273](http://www-1.ibm.com/support/docview.wss?uid=swg1PK63273)
* [http://secunia.com/advisories/29806](http://secunia.com/advisories/29806)
* [http://www.redhat.com/support/errata/RHSA-2008-0009.html](http://www.redhat.com/support/errata/RHSA-2008-0009.html)
* [http://secunia.com/advisories/29988](http://secunia.com/advisories/29988)
* [http://www-1.ibm.com/support/docview.wss?uid=swg24019245](http://www-1.ibm.com/support/docview.wss?uid=swg24019245)
* [http://www.redhat.com/support/errata/RHSA-2008-0261.html](http://www.redhat.com/support/errata/RHSA-2008-0261.html)
* [http://secunia.com/advisories/30356](http://secunia.com/advisories/30356)
* [http://lists.apple.com/archives/security-announce/2008//May/msg00001.html](http://lists.apple.com/archives/security-announce/2008//May/msg00001.html)
* [http://www.us-cert.gov/cas/techalerts/TA08-150A.html](http://www.us-cert.gov/cas/techalerts/TA08-150A.html)
* [http://secunia.com/advisories/30430](http://secunia.com/advisories/30430)
* [http://secunia.com/advisories/31142](http://secunia.com/advisories/31142)
* [http://secunia.com/advisories/30732](http://secunia.com/advisories/30732)
* [http://lists.vmware.com/pipermail/security-announce/2009/000062.html](http://lists.vmware.com/pipermail/security-announce/2009/000062.html)
* [http://www.vupen.com/english/advisories/2008/0178](http://www.vupen.com/english/advisories/2008/0178)
* [http://www.vupen.com/english/advisories/2007/4202](http://www.vupen.com/english/advisories/2007/4202)
* [http://www.vupen.com/english/advisories/2008/1697](http://www.vupen.com/english/advisories/2008/1697)
* [http://www.vupen.com/english/advisories/2007/4301](http://www.vupen.com/english/advisories/2007/4301)
* [http://www.vupen.com/english/advisories/2008/0924/references](http://www.vupen.com/english/advisories/2008/0924/references)
* [http://www.vupen.com/english/advisories/2008/0809/references](http://www.vupen.com/english/advisories/2008/0809/references)
* [http://www.vupen.com/english/advisories/2008/1224/references](http://www.vupen.com/english/advisories/2008/1224/references)
* [http://www.vupen.com/english/advisories/2007/4201](http://www.vupen.com/english/advisories/2007/4201)
* [http://www.vupen.com/english/advisories/2008/1623/references](http://www.vupen.com/english/advisories/2008/1623/references)
* [http://www.vupen.com/english/advisories/2008/0084](http://www.vupen.com/english/advisories/2008/0084)
* [http://www.vupen.com/english/advisories/2008/0398](http://www.vupen.com/english/advisories/2008/0398)
* [http://www.vupen.com/english/advisories/2008/1875/references](http://www.vupen.com/english/advisories/2008/1875/references)
* [http://marc.info/?l=bugtraq&m=130497311408250&w=2](http://marc.info/?l=bugtraq&m=130497311408250&w=2)
* [http://secunia.com/advisories/32800](http://secunia.com/advisories/32800)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/39002](https://exchange.xforce.ibmcloud.com/vulnerabilities/39002)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/39001](https://exchange.xforce.ibmcloud.com/vulnerabilities/39001)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9539](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9539)
* [http://www.securityfocus.com/archive/1/505990/100/0/threaded](http://www.securityfocus.com/archive/1/505990/100/0/threaded)
* [http://www.securityfocus.com/archive/1/498523/100/0/threaded](http://www.securityfocus.com/archive/1/498523/100/0/threaded)
* [http://www.securityfocus.com/archive/1/494428/100/0/threaded](http://www.securityfocus.com/archive/1/494428/100/0/threaded)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2007-6388 Signalée 08/01/2008Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
* [http://httpd.apache.org/security/vulnerabilities_13.html](http://httpd.apache.org/security/vulnerabilities_13.html)
* [http://httpd.apache.org/security/vulnerabilities_20.html](http://httpd.apache.org/security/vulnerabilities_20.html)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://securitytracker.com/id?1019154](http://securitytracker.com/id?1019154)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:014](http://www.mandriva.com/security/advisories?name=MDVSA-2008:014)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:015](http://www.mandriva.com/security/advisories?name=MDVSA-2008:015)
* [http://www.redhat.com/support/errata/RHSA-2008-0004.html](http://www.redhat.com/support/errata/RHSA-2008-0004.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0005.html](http://www.redhat.com/support/errata/RHSA-2008-0005.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0006.html](http://www.redhat.com/support/errata/RHSA-2008-0006.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0007.html](http://www.redhat.com/support/errata/RHSA-2008-0007.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0008.html](http://www.redhat.com/support/errata/RHSA-2008-0008.html)
* [http://www.securityfocus.com/bid/27237](http://www.securityfocus.com/bid/27237)
* [http://secunia.com/advisories/28467](http://secunia.com/advisories/28467)
* [http://secunia.com/advisories/28471](http://secunia.com/advisories/28471)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:016](http://www.mandriva.com/security/advisories?name=MDVSA-2008:016)
* [http://secunia.com/advisories/28526](http://secunia.com/advisories/28526)
* [http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm](http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm)
* [http://secunia.com/advisories/28607](http://secunia.com/advisories/28607)
* [http://www.ubuntu.com/usn/usn-575-1](http://www.ubuntu.com/usn/usn-575-1)
* [http://secunia.com/advisories/28749](http://secunia.com/advisories/28749)
* [http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=689039](http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=689039)
* [http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2008/05/023342-01.pdf](http://www116.nortel.com/pub/repository/CLARIFY/DOCUMENT/2008/05/023342-01.pdf)
* [http://secunia.com/advisories/28965](http://secunia.com/advisories/28965)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748](http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748)
* [http://secunia.com/advisories/28977](http://secunia.com/advisories/28977)
* [http://secunia.com/advisories/28922](http://secunia.com/advisories/28922)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-233623-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-233623-1)
* [http://docs.info.apple.com/article.html?artnum=307562](http://docs.info.apple.com/article.html?artnum=307562)
* [http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html](http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html)
* [http://secunia.com/advisories/29420](http://secunia.com/advisories/29420)
* [http://www-1.ibm.com/support/search.wss?rs=0&q=PK59667&apar=only](http://www-1.ibm.com/support/search.wss?rs=0&q=PK59667&apar=only)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK62966](http://www-1.ibm.com/support/docview.wss?uid=swg1PK62966)
* [http://secunia.com/advisories/29504](http://secunia.com/advisories/29504)
* [http://securityreason.com/securityalert/3541](http://securityreason.com/securityalert/3541)
* [http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html](http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html)
* [http://secunia.com/advisories/29640](http://secunia.com/advisories/29640)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK63273](http://www-1.ibm.com/support/docview.wss?uid=swg1PK63273)
* [http://secunia.com/advisories/29806](http://secunia.com/advisories/29806)
* [http://www.redhat.com/support/errata/RHSA-2008-0009.html](http://www.redhat.com/support/errata/RHSA-2008-0009.html)
* [http://secunia.com/advisories/29988](http://secunia.com/advisories/29988)
* [http://www-1.ibm.com/support/docview.wss?uid=swg24019245](http://www-1.ibm.com/support/docview.wss?uid=swg24019245)
* [http://www.redhat.com/support/errata/RHSA-2008-0261.html](http://www.redhat.com/support/errata/RHSA-2008-0261.html)
* [http://secunia.com/advisories/30356](http://secunia.com/advisories/30356)
* [http://lists.apple.com/archives/security-announce/2008//May/msg00001.html](http://lists.apple.com/archives/security-announce/2008//May/msg00001.html)
* [http://www.us-cert.gov/cas/techalerts/TA08-150A.html](http://www.us-cert.gov/cas/techalerts/TA08-150A.html)
* [http://secunia.com/advisories/30430](http://secunia.com/advisories/30430)
* [http://secunia.com/advisories/31142](http://secunia.com/advisories/31142)
* [http://secunia.com/advisories/30732](http://secunia.com/advisories/30732)
* [http://www.fujitsu.com/global/support/software/security/products-f/interstage-200808e.html](http://www.fujitsu.com/global/support/software/security/products-f/interstage-200808e.html)
* [http://secunia.com/advisories/33200](http://secunia.com/advisories/33200)
* [http://lists.vmware.com/pipermail/security-announce/2009/000062.html](http://lists.vmware.com/pipermail/security-announce/2009/000062.html)
* [http://www.vupen.com/english/advisories/2008/1697](http://www.vupen.com/english/advisories/2008/1697)
* [http://www.vupen.com/english/advisories/2008/0924/references](http://www.vupen.com/english/advisories/2008/0924/references)
* [http://www.vupen.com/english/advisories/2008/0809/references](http://www.vupen.com/english/advisories/2008/0809/references)
* [http://www.vupen.com/english/advisories/2008/0554](http://www.vupen.com/english/advisories/2008/0554)
* [http://www.vupen.com/english/advisories/2008/0986/references](http://www.vupen.com/english/advisories/2008/0986/references)
* [http://www.vupen.com/english/advisories/2008/0047](http://www.vupen.com/english/advisories/2008/0047)
* [http://www.vupen.com/english/advisories/2008/1224/references](http://www.vupen.com/english/advisories/2008/1224/references)
* [http://www.vupen.com/english/advisories/2008/0447/references](http://www.vupen.com/english/advisories/2008/0447/references)
* [http://www.vupen.com/english/advisories/2008/1623/references](http://www.vupen.com/english/advisories/2008/1623/references)
* [http://marc.info/?l=bugtraq&m=130497311408250&w=2](http://marc.info/?l=bugtraq&m=130497311408250&w=2)
* [http://secunia.com/advisories/32800](http://secunia.com/advisories/32800)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/39472](https://exchange.xforce.ibmcloud.com/vulnerabilities/39472)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10272](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10272)
* [http://www.securityfocus.com/archive/1/505990/100/0/threaded](http://www.securityfocus.com/archive/1/505990/100/0/threaded)
* [http://www.securityfocus.com/archive/1/498523/100/0/threaded](http://www.securityfocus.com/archive/1/498523/100/0/threaded)
* [http://www.securityfocus.com/archive/1/494428/100/0/threaded](http://www.securityfocus.com/archive/1/494428/100/0/threaded)
* [http://www.securityfocus.com/archive/1/488082/100/0/threaded](http://www.securityfocus.com/archive/1/488082/100/0/threaded)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2007-6422 Signalée 08/01/2008The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to cause a denial of service (child process crash) via an invalid bb variable.
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0008.html](http://www.redhat.com/support/errata/RHSA-2008-0008.html)
* [http://www.securityfocus.com/bid/27236](http://www.securityfocus.com/bid/27236)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:016](http://www.mandriva.com/security/advisories?name=MDVSA-2008:016)
* [http://secunia.com/advisories/28526](http://secunia.com/advisories/28526)
* [http://www.ubuntu.com/usn/usn-575-1](http://www.ubuntu.com/usn/usn-575-1)
* [http://secunia.com/advisories/28749](http://secunia.com/advisories/28749)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html)
* [http://secunia.com/advisories/28977](http://secunia.com/advisories/28977)
* [http://security.gentoo.org/glsa/glsa-200803-19.xml](http://security.gentoo.org/glsa/glsa-200803-19.xml)
* [http://secunia.com/advisories/29348](http://secunia.com/advisories/29348)
* [http://securityreason.com/securityalert/3523](http://securityreason.com/securityalert/3523)
* [http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html](http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html)
* [http://secunia.com/advisories/29640](http://secunia.com/advisories/29640)
* [http://www.redhat.com/support/errata/RHSA-2008-0009.html](http://www.redhat.com/support/errata/RHSA-2008-0009.html)
* [http://www.vupen.com/english/advisories/2008/0048](http://www.vupen.com/english/advisories/2008/0048)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/39476](https://exchange.xforce.ibmcloud.com/vulnerabilities/39476)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8690](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8690)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10181](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10181)
* [http://www.securityfocus.com/archive/1/486169/100/0/threaded](http://www.securityfocus.com/archive/1/486169/100/0/threaded)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2007-6750 Signalée 27/12/2011The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.
* [http://ha.ckers.org/slowloris/](http://ha.ckers.org/slowloris/)
* [http://archives.neohapsis.com/archives/bugtraq/2007-01/0229.html](http://archives.neohapsis.com/archives/bugtraq/2007-01/0229.html)
* [http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html](http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html)
* [https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017](https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017)
* [https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380](https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380)
* [http://marc.info/?l=bugtraq&m=136612293908376&w=2](http://marc.info/?l=bugtraq&m=136612293908376&w=2)
* [http://www.securityfocus.com/bid/21865](http://www.securityfocus.com/bid/21865)
* [http://www.securitytracker.com/id/1038144](http://www.securitytracker.com/id/1038144)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/72345](https://exchange.xforce.ibmcloud.com/vulnerabilities/72345)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19481](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19481)
* [http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html](http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html) -
Moyenne CVE-2008-0005 Signalée 12/01/2008mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
* [http://securityreason.com/achievement_securityalert/49](http://securityreason.com/achievement_securityalert/49)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:014](http://www.mandriva.com/security/advisories?name=MDVSA-2008:014)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:015](http://www.mandriva.com/security/advisories?name=MDVSA-2008:015)
* [http://www.redhat.com/support/errata/RHSA-2008-0004.html](http://www.redhat.com/support/errata/RHSA-2008-0004.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0005.html](http://www.redhat.com/support/errata/RHSA-2008-0005.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0006.html](http://www.redhat.com/support/errata/RHSA-2008-0006.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0007.html](http://www.redhat.com/support/errata/RHSA-2008-0007.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0008.html](http://www.redhat.com/support/errata/RHSA-2008-0008.html)
* [http://www.securityfocus.com/bid/27234](http://www.securityfocus.com/bid/27234)
* [http://www.securitytracker.com/id?1019185](http://www.securitytracker.com/id?1019185)
* [http://secunia.com/advisories/28467](http://secunia.com/advisories/28467)
* [http://secunia.com/advisories/28471](http://secunia.com/advisories/28471)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:016](http://www.mandriva.com/security/advisories?name=MDVSA-2008:016)
* [http://secunia.com/advisories/28526](http://secunia.com/advisories/28526)
* [http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm](http://support.avaya.com/elmodocs2/security/ASA-2008-032.htm)
* [http://secunia.com/advisories/28607](http://secunia.com/advisories/28607)
* [http://www.ubuntu.com/usn/usn-575-1](http://www.ubuntu.com/usn/usn-575-1)
* [http://secunia.com/advisories/28749](http://secunia.com/advisories/28749)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html)
* [http://secunia.com/advisories/28977](http://secunia.com/advisories/28977)
* [http://security.gentoo.org/glsa/glsa-200803-19.xml](http://security.gentoo.org/glsa/glsa-200803-19.xml)
* [http://secunia.com/advisories/29348](http://secunia.com/advisories/29348)
* [http://docs.info.apple.com/article.html?artnum=307562](http://docs.info.apple.com/article.html?artnum=307562)
* [http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html](http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html)
* [http://secunia.com/advisories/29420](http://secunia.com/advisories/29420)
* [http://securityreason.com/securityalert/3526](http://securityreason.com/securityalert/3526)
* [http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html](http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html)
* [http://secunia.com/advisories/29640](http://secunia.com/advisories/29640)
* [http://www.redhat.com/support/errata/RHSA-2008-0009.html](http://www.redhat.com/support/errata/RHSA-2008-0009.html)
* [http://secunia.com/advisories/30732](http://secunia.com/advisories/30732)
* [http://secunia.com/advisories/35650](http://secunia.com/advisories/35650)
* [http://marc.info/?l=bugtraq&m=124654546101607&w=2](http://marc.info/?l=bugtraq&m=124654546101607&w=2)
* [http://lists.vmware.com/pipermail/security-announce/2009/000062.html](http://lists.vmware.com/pipermail/security-announce/2009/000062.html)
* [http://marc.info/?l=bugtraq&m=125631037611762&w=2](http://marc.info/?l=bugtraq&m=125631037611762&w=2)
* [http://www.vupen.com/english/advisories/2008/0924/references](http://www.vupen.com/english/advisories/2008/0924/references)
* [http://www.vupen.com/english/advisories/2008/1875/references](http://www.vupen.com/english/advisories/2008/1875/references)
* [http://marc.info/?l=bugtraq&m=130497311408250&w=2](http://marc.info/?l=bugtraq&m=130497311408250&w=2)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/39615](https://exchange.xforce.ibmcloud.com/vulnerabilities/39615)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10812](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10812)
* [http://www.securityfocus.com/archive/1/505990/100/0/threaded](http://www.securityfocus.com/archive/1/505990/100/0/threaded)
* [http://www.securityfocus.com/archive/1/486167/100/0/threaded](http://www.securityfocus.com/archive/1/486167/100/0/threaded)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2008-0455 Signalée 25/01/2008Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a name containing XSS sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
* [http://www.mindedsecurity.com/MSA01150108.html](http://www.mindedsecurity.com/MSA01150108.html)
* [http://www.securityfocus.com/bid/27409](http://www.securityfocus.com/bid/27409)
* [http://securitytracker.com/id?1019256](http://securitytracker.com/id?1019256)
* [http://security.gentoo.org/glsa/glsa-200803-19.xml](http://security.gentoo.org/glsa/glsa-200803-19.xml)
* [http://secunia.com/advisories/29348](http://secunia.com/advisories/29348)
* [http://securityreason.com/securityalert/3575](http://securityreason.com/securityalert/3575)
* [http://rhn.redhat.com/errata/RHSA-2012-1592.html](http://rhn.redhat.com/errata/RHSA-2012-1592.html)
* [http://rhn.redhat.com/errata/RHSA-2012-1591.html](http://rhn.redhat.com/errata/RHSA-2012-1591.html)
* [http://secunia.com/advisories/51607](http://secunia.com/advisories/51607)
* [http://rhn.redhat.com/errata/RHSA-2012-1594.html](http://rhn.redhat.com/errata/RHSA-2012-1594.html)
* [http://rhn.redhat.com/errata/RHSA-2013-0130.html](http://rhn.redhat.com/errata/RHSA-2013-0130.html)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/39867](https://exchange.xforce.ibmcloud.com/vulnerabilities/39867)
* [http://www.securityfocus.com/archive/1/486847/100/0/threaded](http://www.securityfocus.com/archive/1/486847/100/0/threaded)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2008-2168 Signalée 13/05/2008Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
* [http://www.securityfocus.com/bid/29112](http://www.securityfocus.com/bid/29112)
* [http://secunia.com/advisories/31651](http://secunia.com/advisories/31651)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432)
* [http://securityreason.com/securityalert/3889](http://securityreason.com/securityalert/3889)
* [http://www.ubuntu.com/usn/USN-731-1](http://www.ubuntu.com/usn/USN-731-1)
* [http://secunia.com/advisories/34219](http://secunia.com/advisories/34219)
* [http://secunia.com/advisories/35650](http://secunia.com/advisories/35650)
* [http://marc.info/?l=bugtraq&m=124654546101607&w=2](http://marc.info/?l=bugtraq&m=124654546101607&w=2)
* [http://marc.info/?l=bugtraq&m=125631037611762&w=2](http://marc.info/?l=bugtraq&m=125631037611762&w=2)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/42303](https://exchange.xforce.ibmcloud.com/vulnerabilities/42303)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5143](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5143)
* [http://www.securityfocus.com/archive/1/491967/100/0/threaded](http://www.securityfocus.com/archive/1/491967/100/0/threaded)
* [http://www.securityfocus.com/archive/1/491930/100/0/threaded](http://www.securityfocus.com/archive/1/491930/100/0/threaded)
* [http://www.securityfocus.com/archive/1/491901/100/0/threaded](http://www.securityfocus.com/archive/1/491901/100/0/threaded)
* [http://www.securityfocus.com/archive/1/491862/100/0/threaded](http://www.securityfocus.com/archive/1/491862/100/0/threaded) -
Moyenne CVE-2008-2364 Signalée 13/06/2008The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&r2=666153&pathrev=666154](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&r2=666153&pathrev=666154)
* [http://www.securityfocus.com/bid/29653](http://www.securityfocus.com/bid/29653)
* [http://secunia.com/advisories/30621](http://secunia.com/advisories/30621)
* [https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00153.html](https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00153.html)
* [http://secunia.com/advisories/31416](http://secunia.com/advisories/31416)
* [http://secunia.com/advisories/31404](http://secunia.com/advisories/31404)
* [http://secunia.com/advisories/31026](http://secunia.com/advisories/31026)
* [https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00055.html](https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00055.html)
* [http://security.gentoo.org/glsa/glsa-200807-06.xml](http://security.gentoo.org/glsa/glsa-200807-06.xml)
* [http://www.securitytracker.com/id?1020267](http://www.securitytracker.com/id?1020267)
* [http://secunia.com/advisories/31651](http://secunia.com/advisories/31651)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432)
* [http://www-01.ibm.com/support/docview.wss?uid=swg27008517](http://www-01.ibm.com/support/docview.wss?uid=swg27008517)
* [http://secunia.com/advisories/31904](http://secunia.com/advisories/31904)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:195](http://www.mandriva.com/security/advisories?name=MDVSA-2008:195)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK67579](http://www-1.ibm.com/support/docview.wss?uid=swg1PK67579)
* [http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html](http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html)
* [http://www.securityfocus.com/bid/31681](http://www.securityfocus.com/bid/31681)
* [http://support.apple.com/kb/HT3216](http://support.apple.com/kb/HT3216)
* [http://secunia.com/advisories/32222](http://secunia.com/advisories/32222)
* [http://secunia.com/advisories/32685](http://secunia.com/advisories/32685)
* [http://rhn.redhat.com/errata/RHSA-2008-0967.html](http://rhn.redhat.com/errata/RHSA-2008-0967.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0966.html](http://www.redhat.com/support/errata/RHSA-2008-0966.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:237](http://www.mandriva.com/security/advisories?name=MDVSA-2008:237)
* [http://marc.info/?l=bugtraq&m=123376588623823&w=2](http://marc.info/?l=bugtraq&m=123376588623823&w=2)
* [http://secunia.com/advisories/33156](http://secunia.com/advisories/33156)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1)
* [http://secunia.com/advisories/33797](http://secunia.com/advisories/33797)
* [http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328](http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328)
* [http://secunia.com/advisories/32838](http://secunia.com/advisories/32838)
* [http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html)
* [http://www.ubuntu.com/usn/USN-731-1](http://www.ubuntu.com/usn/USN-731-1)
* [http://secunia.com/advisories/34259](http://secunia.com/advisories/34259)
* [http://secunia.com/advisories/34219](http://secunia.com/advisories/34219)
* [http://secunia.com/advisories/34418](http://secunia.com/advisories/34418)
* [http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html](http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html)
* [http://marc.info/?l=bugtraq&m=125631037611762&w=2](http://marc.info/?l=bugtraq&m=125631037611762&w=2)
* [http://www.vupen.com/english/advisories/2008/2780](http://www.vupen.com/english/advisories/2008/2780)
* [http://www.vupen.com/english/advisories/2009/0320](http://www.vupen.com/english/advisories/2009/0320)
* [http://www.vupen.com/english/advisories/2008/1798](http://www.vupen.com/english/advisories/2008/1798)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/42987](https://exchange.xforce.ibmcloud.com/vulnerabilities/42987)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9577](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9577)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6084](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6084)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11713](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11713)
* [http://www.securityfocus.com/archive/1/498567/100/0/threaded](http://www.securityfocus.com/archive/1/498567/100/0/threaded)
* [http://www.securityfocus.com/archive/1/494858/100/0/threaded](http://www.securityfocus.com/archive/1/494858/100/0/threaded)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2008-2939 Signalée 06/08/2008Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
* [http://svn.apache.org/viewvc?view=rev&revision=682868](http://svn.apache.org/viewvc?view=rev&revision=682868)
* [http://svn.apache.org/viewvc?view=rev&revision=682871](http://svn.apache.org/viewvc?view=rev&revision=682871)
* [http://www.securityfocus.com/bid/30560](http://www.securityfocus.com/bid/30560)
* [http://secunia.com/advisories/31384](http://secunia.com/advisories/31384)
* [http://www.rapid7.com/advisories/R7-0033](http://www.rapid7.com/advisories/R7-0033)
* [http://secunia.com/advisories/31673](http://secunia.com/advisories/31673)
* [http://www.kb.cert.org/vuls/id/663763](http://www.kb.cert.org/vuls/id/663763)
* [http://www.securitytracker.com/id?1020635](http://www.securitytracker.com/id?1020635)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197](http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197)
* [http://svn.apache.org/viewvc?view=rev&revision=682870](http://svn.apache.org/viewvc?view=rev&revision=682870)
* [http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937](http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:195](http://www.mandriva.com/security/advisories?name=MDVSA-2008:195)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:194](http://www.mandriva.com/security/advisories?name=MDVSA-2008:194)
* [http://secunia.com/advisories/32685](http://secunia.com/advisories/32685)
* [http://rhn.redhat.com/errata/RHSA-2008-0967.html](http://rhn.redhat.com/errata/RHSA-2008-0967.html)
* [http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.html](http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0966.html](http://www.redhat.com/support/errata/RHSA-2008-0966.html)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1)
* [http://secunia.com/advisories/33156](http://secunia.com/advisories/33156)
* [http://marc.info/?l=bugtraq&m=123376588623823&w=2](http://marc.info/?l=bugtraq&m=123376588623823&w=2)
* [http://secunia.com/advisories/33797](http://secunia.com/advisories/33797)
* [http://secunia.com/advisories/32838](http://secunia.com/advisories/32838)
* [http://wiki.rpath.com/Advisories:rPSA-2008-0327](http://wiki.rpath.com/Advisories:rPSA-2008-0327)
* [http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328](http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328)
* [http://www.ubuntu.com/usn/USN-731-1](http://www.ubuntu.com/usn/USN-731-1)
* [http://secunia.com/advisories/34219](http://secunia.com/advisories/34219)
* [http://lists.apple.com/archives/security-announce/2009/May/msg00002.html](http://lists.apple.com/archives/security-announce/2009/May/msg00002.html)
* [http://support.apple.com/kb/HT3549](http://support.apple.com/kb/HT3549)
* [http://www.us-cert.gov/cas/techalerts/TA09-133A.html](http://www.us-cert.gov/cas/techalerts/TA09-133A.html)
* [http://secunia.com/advisories/35074](http://secunia.com/advisories/35074)
* [http://www.vupen.com/english/advisories/2009/1297](http://www.vupen.com/english/advisories/2009/1297)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:124](http://www.mandriva.com/security/advisories?name=MDVSA-2009:124)
* [http://marc.info/?l=bugtraq&m=125631037611762&w=2](http://marc.info/?l=bugtraq&m=125631037611762&w=2)
* [http://www.vupen.com/english/advisories/2009/0320](http://www.vupen.com/english/advisories/2009/0320)
* [http://www.vupen.com/english/advisories/2008/2315](http://www.vupen.com/english/advisories/2008/2315)
* [http://www.vupen.com/english/advisories/2008/2461](http://www.vupen.com/english/advisories/2008/2461)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/44223](https://exchange.xforce.ibmcloud.com/vulnerabilities/44223)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7716](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7716)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11316](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11316)
* [http://www.securityfocus.com/archive/1/498567/100/0/threaded](http://www.securityfocus.com/archive/1/498567/100/0/threaded)
* [http://www.securityfocus.com/archive/1/498566/100/0/threaded](http://www.securityfocus.com/archive/1/498566/100/0/threaded)
* [http://www.securityfocus.com/archive/1/495180/100/0/threaded](http://www.securityfocus.com/archive/1/495180/100/0/threaded)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2009-0023 Signalée 08/06/2009The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.
* [http://www.debian.org/security/2009/dsa-1812](http://www.debian.org/security/2009/dsa-1812)
* [http://www.securityfocus.com/bid/35221](http://www.securityfocus.com/bid/35221)
* [http://secunia.com/advisories/35284](http://secunia.com/advisories/35284)
* [https://bugzilla.redhat.com/show_bug.cgi?id=503928](https://bugzilla.redhat.com/show_bug.cgi?id=503928)
* [http://secunia.com/advisories/35360](http://secunia.com/advisories/35360)
* [http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3](http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3)
* [http://svn.apache.org/viewvc?view=rev&revision=779880](http://svn.apache.org/viewvc?view=rev&revision=779880)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:131](http://www.mandriva.com/security/advisories?name=MDVSA-2009:131)
* [http://www.ubuntu.com/usn/usn-786-1](http://www.ubuntu.com/usn/usn-786-1)
* [http://www.redhat.com/support/errata/RHSA-2009-1108.html](http://www.redhat.com/support/errata/RHSA-2009-1108.html)
* [http://www.redhat.com/support/errata/RHSA-2009-1107.html](http://www.redhat.com/support/errata/RHSA-2009-1107.html)
* [http://secunia.com/advisories/35444](http://secunia.com/advisories/35444)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.538210](http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.538210)
* [http://secunia.com/advisories/34724](http://secunia.com/advisories/34724)
* [http://secunia.com/advisories/35487](http://secunia.com/advisories/35487)
* [http://secunia.com/advisories/35395](http://secunia.com/advisories/35395)
* [http://www.ubuntu.com/usn/usn-787-1](http://www.ubuntu.com/usn/usn-787-1)
* [https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html](https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html](https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html](https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html)
* [http://secunia.com/advisories/35565](http://secunia.com/advisories/35565)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241](http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241)
* [http://security.gentoo.org/glsa/glsa-200907-03.xml](http://security.gentoo.org/glsa/glsa-200907-03.xml)
* [http://secunia.com/advisories/35710](http://secunia.com/advisories/35710)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341](http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341)
* [http://secunia.com/advisories/35797](http://secunia.com/advisories/35797)
* [http://secunia.com/advisories/35843](http://secunia.com/advisories/35843)
* [http://www.vupen.com/english/advisories/2009/1907](http://www.vupen.com/english/advisories/2009/1907)
* [http://support.apple.com/kb/HT3937](http://support.apple.com/kb/HT3937)
* [http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html](http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html)
* [http://www.vupen.com/english/advisories/2009/3184](http://www.vupen.com/english/advisories/2009/3184)
* [http://www-01.ibm.com/support/docview.wss?uid=swg27014463](http://www-01.ibm.com/support/docview.wss?uid=swg27014463)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478](http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478)
* [http://secunia.com/advisories/37221](http://secunia.com/advisories/37221)
* [http://wiki.rpath.com/Advisories:rPSA-2009-0144](http://wiki.rpath.com/Advisories:rPSA-2009-0144)
* [http://marc.info/?l=bugtraq&m=129190899612998&w=2](http://marc.info/?l=bugtraq&m=129190899612998&w=2)
* [http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html](http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/50964](https://exchange.xforce.ibmcloud.com/vulnerabilities/50964)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12321](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12321)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10968](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10968)
* [http://www.securityfocus.com/archive/1/507855/100/0/threaded](http://www.securityfocus.com/archive/1/507855/100/0/threaded)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2009-1956 Signalée 08/06/2009Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
* [http://svn.apache.org/viewvc?view=rev&revision=768417](http://svn.apache.org/viewvc?view=rev&revision=768417)
* [http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3](http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3)
* [https://bugzilla.redhat.com/show_bug.cgi?id=504390](https://bugzilla.redhat.com/show_bug.cgi?id=504390)
* [http://www.openwall.com/lists/oss-security/2009/06/06/1](http://www.openwall.com/lists/oss-security/2009/06/06/1)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:131](http://www.mandriva.com/security/advisories?name=MDVSA-2009:131)
* [http://www.ubuntu.com/usn/usn-786-1](http://www.ubuntu.com/usn/usn-786-1)
* [http://www.securityfocus.com/bid/35251](http://www.securityfocus.com/bid/35251)
* [http://www.redhat.com/support/errata/RHSA-2009-1107.html](http://www.redhat.com/support/errata/RHSA-2009-1107.html)
* [http://www.redhat.com/support/errata/RHSA-2009-1108.html](http://www.redhat.com/support/errata/RHSA-2009-1108.html)
* [http://secunia.com/advisories/34724](http://secunia.com/advisories/34724)
* [http://secunia.com/advisories/35487](http://secunia.com/advisories/35487)
* [http://secunia.com/advisories/35395](http://secunia.com/advisories/35395)
* [http://www.ubuntu.com/usn/usn-787-1](http://www.ubuntu.com/usn/usn-787-1)
* [https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html](https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01228.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html](https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01201.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html](https://www.redhat.com/archives/fedora-package-announce/2009-June/msg01173.html)
* [http://secunia.com/advisories/35565](http://secunia.com/advisories/35565)
* [http://secunia.com/advisories/35710](http://secunia.com/advisories/35710)
* [http://secunia.com/advisories/35843](http://secunia.com/advisories/35843)
* [http://security.gentoo.org/glsa/glsa-200907-03.xml](http://security.gentoo.org/glsa/glsa-200907-03.xml)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241](http://www-01.ibm.com/support/docview.wss?uid=swg1PK91241)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341](http://www-01.ibm.com/support/docview.wss?uid=swg1PK88341)
* [http://secunia.com/advisories/35797](http://secunia.com/advisories/35797)
* [http://secunia.com/advisories/35284](http://secunia.com/advisories/35284)
* [http://www.vupen.com/english/advisories/2009/1907](http://www.vupen.com/english/advisories/2009/1907)
* [http://support.apple.com/kb/HT3937](http://support.apple.com/kb/HT3937)
* [http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html](http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html)
* [http://www.vupen.com/english/advisories/2009/3184](http://www.vupen.com/english/advisories/2009/3184)
* [http://www-01.ibm.com/support/docview.wss?uid=swg27014463](http://www-01.ibm.com/support/docview.wss?uid=swg27014463)
* [http://secunia.com/advisories/37221](http://secunia.com/advisories/37221)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478](http://www-01.ibm.com/support/docview.wss?uid=swg1PK99478)
* [http://marc.info/?l=bugtraq&m=129190899612998&w=2](http://marc.info/?l=bugtraq&m=129190899612998&w=2)
* [http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html](http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12237](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12237)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11567](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11567)
* [http://www.mail-archive.com/dev%40apr.apache.org/msg21592.html](http://www.mail-archive.com/dev%40apr.apache.org/msg21592.html)
* [http://www.mail-archive.com/dev%40apr.apache.org/msg21591.html](http://www.mail-archive.com/dev%40apr.apache.org/msg21591.html)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2009-3095 Signalée 08/09/2009The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
* [http://intevydis.com/vd-list.shtml](http://intevydis.com/vd-list.shtml)
* [http://secunia.com/advisories/37152](http://secunia.com/advisories/37152)
* [http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html)
* [http://www.debian.org/security/2009/dsa-1934](http://www.debian.org/security/2009/dsa-1934)
* [http://wiki.rpath.com/Advisories:rPSA-2009-0155](http://wiki.rpath.com/Advisories:rPSA-2009-0155)
* [https://bugzilla.redhat.com/show_bug.cgi?id=522209](https://bugzilla.redhat.com/show_bug.cgi?id=522209)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html)
* [http://support.apple.com/kb/HT4077](http://support.apple.com/kb/HT4077)
* [http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html](http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html)
* [http://marc.info/?l=bugtraq&m=130497311408250&w=2](http://marc.info/?l=bugtraq&m=130497311408250&w=2)
* [http://marc.info/?l=bugtraq&m=126998684522511&w=2](http://marc.info/?l=bugtraq&m=126998684522511&w=2)
* [http://marc.info/?l=bugtraq&m=133355494609819&w=2](http://marc.info/?l=bugtraq&m=133355494609819&w=2)
* [http://marc.info/?l=bugtraq&m=127557640302499&w=2](http://marc.info/?l=bugtraq&m=127557640302499&w=2)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9363](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9363)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8662](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8662)
* [http://www.securityfocus.com/archive/1/508075/100/0/threaded](http://www.securityfocus.com/archive/1/508075/100/0/threaded)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2009-3555 Signalée 09/11/2009The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.
* [http://www.tombom.co.uk/blog/?p=85](http://www.tombom.co.uk/blog/?p=85)
* [http://www.ietf.org/mail-archive/web/tls/current/msg03948.html](http://www.ietf.org/mail-archive/web/tls/current/msg03948.html)
* [http://secunia.com/advisories/37292](http://secunia.com/advisories/37292)
* [https://bugzilla.mozilla.org/show_bug.cgi?id=526689](https://bugzilla.mozilla.org/show_bug.cgi?id=526689)
* [http://extendedsubset.com/?p=8](http://extendedsubset.com/?p=8)
* [http://www.ietf.org/mail-archive/web/tls/current/msg03928.html](http://www.ietf.org/mail-archive/web/tls/current/msg03928.html)
* [http://www.vupen.com/english/advisories/2009/3165](http://www.vupen.com/english/advisories/2009/3165)
* [http://marc.info/?l=cryptography&m=125752275331877&w=2](http://marc.info/?l=cryptography&m=125752275331877&w=2)
* [http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during](http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during)
* [http://www.vupen.com/english/advisories/2009/3164](http://www.vupen.com/english/advisories/2009/3164)
* [http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2](http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2)
* [http://kbase.redhat.com/faq/docs/DOC-20491](http://kbase.redhat.com/faq/docs/DOC-20491)
* [https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt](https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt)
* [http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html](http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html)
* [http://www.securityfocus.com/bid/36935](http://www.securityfocus.com/bid/36935)
* [http://www.betanews.com/article/1257452450](http://www.betanews.com/article/1257452450)
* [http://www.openwall.com/lists/oss-security/2009/11/06/3](http://www.openwall.com/lists/oss-security/2009/11/06/3)
* [http://www.openwall.com/lists/oss-security/2009/11/05/3](http://www.openwall.com/lists/oss-security/2009/11/05/3)
* [https://bugzilla.redhat.com/show_bug.cgi?id=533125](https://bugzilla.redhat.com/show_bug.cgi?id=533125)
* [http://www.links.org/?p=780](http://www.links.org/?p=780)
* [http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html](http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html)
* [http://secunia.com/advisories/37291](http://secunia.com/advisories/37291)
* [http://www.openwall.com/lists/oss-security/2009/11/05/5](http://www.openwall.com/lists/oss-security/2009/11/05/5)
* [http://www.openwall.com/lists/oss-security/2009/11/07/3](http://www.openwall.com/lists/oss-security/2009/11/07/3)
* [http://extendedsubset.com/Renegotiating_TLS.pdf](http://extendedsubset.com/Renegotiating_TLS.pdf)
* [http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml](http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml)
* [http://www.securitytracker.com/id?1023163](http://www.securitytracker.com/id?1023163)
* [http://www.kb.cert.org/vuls/id/120541](http://www.kb.cert.org/vuls/id/120541)
* [http://www.links.org/?p=789](http://www.links.org/?p=789)
* [http://seclists.org/fulldisclosure/2009/Nov/139](http://seclists.org/fulldisclosure/2009/Nov/139)
* [http://blogs.iss.net/archive/sslmitmiscsrf.html](http://blogs.iss.net/archive/sslmitmiscsrf.html)
* [http://www.links.org/?p=786](http://www.links.org/?p=786)
* [http://www.vupen.com/english/advisories/2009/3220](http://www.vupen.com/english/advisories/2009/3220)
* [http://support.citrix.com/article/CTX123359](http://support.citrix.com/article/CTX123359)
* [http://secunia.com/advisories/37320](http://secunia.com/advisories/37320)
* [http://www.vupen.com/english/advisories/2009/3205](http://www.vupen.com/english/advisories/2009/3205)
* [http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html](http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html)
* [http://securitytracker.com/id?1023148](http://securitytracker.com/id?1023148)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1](http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1)
* [http://www.debian.org/security/2009/dsa-1934](http://www.debian.org/security/2009/dsa-1934)
* [http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html](http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html)
* [http://sysoev.ru/nginx/patch.cve-2009-3555.txt](http://sysoev.ru/nginx/patch.cve-2009-3555.txt)
* [http://www.openwall.com/lists/oss-security/2009/11/20/1](http://www.openwall.com/lists/oss-security/2009/11/20/1)
* [http://www.openwall.com/lists/oss-security/2009/11/23/10](http://www.openwall.com/lists/oss-security/2009/11/23/10)
* [http://wiki.rpath.com/Advisories:rPSA-2009-0155](http://wiki.rpath.com/Advisories:rPSA-2009-0155)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html)
* [http://www.securitytracker.com/id?1023272](http://www.securitytracker.com/id?1023272)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html)
* [http://www.securitytracker.com/id?1023271](http://www.securitytracker.com/id?1023271)
* [http://openbsd.org/errata45.html#010_openssl](http://openbsd.org/errata45.html#010_openssl)
* [http://www.securitytracker.com/id?1023207](http://www.securitytracker.com/id?1023207)
* [http://secunia.com/advisories/37656](http://secunia.com/advisories/37656)
* [http://www.securitytracker.com/id?1023211](http://www.securitytracker.com/id?1023211)
* [http://www.securitytracker.com/id?1023218](http://www.securitytracker.com/id?1023218)
* [http://www.vupen.com/english/advisories/2009/3353](http://www.vupen.com/english/advisories/2009/3353)
* [http://www.securitytracker.com/id?1023209](http://www.securitytracker.com/id?1023209)
* [http://www.securitytracker.com/id?1023273](http://www.securitytracker.com/id?1023273)
* [http://security.gentoo.org/glsa/glsa-200912-01.xml](http://security.gentoo.org/glsa/glsa-200912-01.xml)
* [http://www.securitytracker.com/id?1023215](http://www.securitytracker.com/id?1023215)
* [http://www.ingate.com/Relnote.php?ver=481](http://www.ingate.com/Relnote.php?ver=481)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html)
* [http://secunia.com/advisories/37504](http://secunia.com/advisories/37504)
* [http://www.securitytracker.com/id?1023208](http://www.securitytracker.com/id?1023208)
* [http://www.securitytracker.com/id?1023212](http://www.securitytracker.com/id?1023212)
* [http://www.securitytracker.com/id?1023243](http://www.securitytracker.com/id?1023243)
* [https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html](https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html)
* [http://clicky.me/tlsvuln](http://clicky.me/tlsvuln)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html)
* [http://www.securitytracker.com/id?1023204](http://www.securitytracker.com/id?1023204)
* [http://secunia.com/advisories/37501](http://secunia.com/advisories/37501)
* [http://www.securitytracker.com/id?1023217](http://www.securitytracker.com/id?1023217)
* [http://www.securitytracker.com/id?1023210](http://www.securitytracker.com/id?1023210)
* [http://www.securitytracker.com/id?1023274](http://www.securitytracker.com/id?1023274)
* [http://secunia.com/advisories/37675](http://secunia.com/advisories/37675)
* [http://www.securitytracker.com/id?1023205](http://www.securitytracker.com/id?1023205)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686)
* [http://www.securitytracker.com/id?1023275](http://www.securitytracker.com/id?1023275)
* [http://www.securitytracker.com/id?1023216](http://www.securitytracker.com/id?1023216)
* [http://openbsd.org/errata46.html#004_openssl](http://openbsd.org/errata46.html#004_openssl)
* [http://www.securitytracker.com/id?1023270](http://www.securitytracker.com/id?1023270)
* [http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html](http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html)
* [http://www.securitytracker.com/id?1023206](http://www.securitytracker.com/id?1023206)
* [http://osvdb.org/60521](http://osvdb.org/60521)
* [http://www.securitytracker.com/id?1023219](http://www.securitytracker.com/id?1023219)
* [http://www.vupen.com/english/advisories/2009/3354](http://www.vupen.com/english/advisories/2009/3354)
* [http://secunia.com/advisories/37604](http://secunia.com/advisories/37604)
* [http://secunia.com/advisories/37859](http://secunia.com/advisories/37859)
* [http://www.vupen.com/english/advisories/2009/3484](http://www.vupen.com/english/advisories/2009/3484)
* [http://www.vupen.com/english/advisories/2009/3587](http://www.vupen.com/english/advisories/2009/3587)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html)
* [http://www-01.ibm.com/support/docview.wss?uid=swg24025312](http://www-01.ibm.com/support/docview.wss?uid=swg24025312)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html)
* [http://secunia.com/advisories/37640](http://secunia.com/advisories/37640)
* [http://osvdb.org/60972](http://osvdb.org/60972)
* [http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only](http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only)
* [http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c](http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c)
* [http://www.vupen.com/english/advisories/2009/3521](http://www.vupen.com/english/advisories/2009/3521)
* [http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html](http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html)
* [http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html](http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html)
* [http://secunia.com/advisories/38056](http://secunia.com/advisories/38056)
* [http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES](http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES)
* [http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released](http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released)
* [http://support.apple.com/kb/HT4004](http://support.apple.com/kb/HT4004)
* [http://secunia.com/advisories/38241](http://secunia.com/advisories/38241)
* [http://www.vupen.com/english/advisories/2010/0173](http://www.vupen.com/english/advisories/2010/0173)
* [http://secunia.com/advisories/38484](http://secunia.com/advisories/38484)
* [http://osvdb.org/62210](http://osvdb.org/62210)
* [http://www.arubanetworks.com/support/alerts/aid-020810.txt](http://www.arubanetworks.com/support/alerts/aid-020810.txt)
* [http://www.vupen.com/english/advisories/2010/0086](http://www.vupen.com/english/advisories/2010/0086)
* [http://secunia.com/advisories/38003](http://secunia.com/advisories/38003)
* [http://support.avaya.com/css/P8/documents/100070150](http://support.avaya.com/css/P8/documents/100070150)
* [http://www.securitytracker.com/id?1023428](http://www.securitytracker.com/id?1023428)
* [http://www.securitytracker.com/id?1023427](http://www.securitytracker.com/id?1023427)
* [http://www.securitytracker.com/id?1023411](http://www.securitytracker.com/id?1023411)
* [http://www.securitytracker.com/id?1023426](http://www.securitytracker.com/id?1023426)
* [http://www.redhat.com/support/errata/RHSA-2010-0119.html](http://www.redhat.com/support/errata/RHSA-2010-0119.html)
* [http://secunia.com/advisories/38687](http://secunia.com/advisories/38687)
* [http://secunia.com/advisories/38020](http://secunia.com/advisories/38020)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1](http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1](http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1)
* [http://www.redhat.com/support/errata/RHSA-2010-0167.html](http://www.redhat.com/support/errata/RHSA-2010-0167.html)
* [http://www.redhat.com/support/errata/RHSA-2010-0155.html](http://www.redhat.com/support/errata/RHSA-2010-0155.html)
* [http://www.vupen.com/english/advisories/2010/0748](http://www.vupen.com/english/advisories/2010/0748)
* [http://secunia.com/advisories/39243](http://secunia.com/advisories/39243)
* [http://secunia.com/advisories/39136](http://secunia.com/advisories/39136)
* [https://bugzilla.mozilla.org/show_bug.cgi?id=545755](https://bugzilla.mozilla.org/show_bug.cgi?id=545755)
* [http://www.mozilla.org/security/announce/2010/mfsa2010-22.html](http://www.mozilla.org/security/announce/2010/mfsa2010-22.html)
* [http://secunia.com/advisories/39242](http://secunia.com/advisories/39242)
* [http://www.redhat.com/support/errata/RHSA-2010-0338.html](http://www.redhat.com/support/errata/RHSA-2010-0338.html)
* [http://www.redhat.com/support/errata/RHSA-2010-0339.html](http://www.redhat.com/support/errata/RHSA-2010-0339.html)
* [http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html)
* [http://www.redhat.com/support/errata/RHSA-2010-0337.html](http://www.redhat.com/support/errata/RHSA-2010-0337.html)
* [http://secunia.com/advisories/39317](http://secunia.com/advisories/39317)
* [http://ubuntu.com/usn/usn-923-1](http://ubuntu.com/usn/usn-923-1)
* [http://secunia.com/advisories/39292](http://secunia.com/advisories/39292)
* [http://secunia.com/advisories/37453](http://secunia.com/advisories/37453)
* [http://www.securitytracker.com/id?1023224](http://www.securitytracker.com/id?1023224)
* [http://secunia.com/advisories/37383](http://secunia.com/advisories/37383)
* [http://secunia.com/advisories/37399](http://secunia.com/advisories/37399)
* [http://www.vupen.com/english/advisories/2009/3310](http://www.vupen.com/english/advisories/2009/3310)
* [http://www.vupen.com/english/advisories/2009/3313](http://www.vupen.com/english/advisories/2009/3313)
* [http://www.securitytracker.com/id?1023214](http://www.securitytracker.com/id?1023214)
* [http://www.securitytracker.com/id?1023213](http://www.securitytracker.com/id?1023213)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446](http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446)
* [http://www.vupen.com/english/advisories/2010/0848](http://www.vupen.com/english/advisories/2010/0848)
* [http://secunia.com/advisories/38781](http://secunia.com/advisories/38781)
* [http://secunia.com/advisories/39278](http://secunia.com/advisories/39278)
* [http://www.redhat.com/support/errata/RHSA-2010-0130.html](http://www.redhat.com/support/errata/RHSA-2010-0130.html)
* [http://www.ubuntu.com/usn/USN-927-1](http://www.ubuntu.com/usn/USN-927-1)
* [http://secunia.com/advisories/39500](http://secunia.com/advisories/39500)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848](http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848)
* [http://www.vupen.com/english/advisories/2010/0982](http://www.vupen.com/english/advisories/2010/0982)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21426108](http://www-01.ibm.com/support/docview.wss?uid=swg21426108)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2010:076](http://www.mandriva.com/security/advisories?name=MDVSA-2010:076)
* [http://www.vupen.com/english/advisories/2010/0933](http://www.vupen.com/english/advisories/2010/0933)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2010:084](http://www.mandriva.com/security/advisories?name=MDVSA-2010:084)
* [http://secunia.com/advisories/39628](http://secunia.com/advisories/39628)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247](http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html)
* [http://secunia.com/advisories/39461](http://secunia.com/advisories/39461)
* [http://www.vupen.com/english/advisories/2010/0916](http://www.vupen.com/english/advisories/2010/0916)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2010:089](http://www.mandriva.com/security/advisories?name=MDVSA-2010:089)
* [http://www.vupen.com/english/advisories/2010/1054](http://www.vupen.com/english/advisories/2010/1054)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html)
* [http://support.avaya.com/css/P8/documents/100081611](http://support.avaya.com/css/P8/documents/100081611)
* [http://www.redhat.com/support/errata/RHSA-2010-0165.html](http://www.redhat.com/support/errata/RHSA-2010-0165.html)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html)
* [http://secunia.com/advisories/39632](http://secunia.com/advisories/39632)
* [http://secunia.com/advisories/39713](http://secunia.com/advisories/39713)
* [http://www.vupen.com/english/advisories/2010/0994](http://www.vupen.com/english/advisories/2010/0994)
* [http://marc.info/?l=bugtraq&m=127419602507642&w=2](http://marc.info/?l=bugtraq&m=127419602507642&w=2)
* [http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html)
* [http://www.vupen.com/english/advisories/2010/1107](http://www.vupen.com/english/advisories/2010/1107)
* [http://lists.apple.com/archives/security-announce/2010//May/msg00002.html](http://lists.apple.com/archives/security-announce/2010//May/msg00002.html)
* [http://secunia.com/advisories/39819](http://secunia.com/advisories/39819)
* [http://lists.apple.com/archives/security-announce/2010//May/msg00001.html](http://lists.apple.com/archives/security-announce/2010//May/msg00001.html)
* [http://support.apple.com/kb/HT4170](http://support.apple.com/kb/HT4170)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1](http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1)
* [http://support.apple.com/kb/HT4171](http://support.apple.com/kb/HT4171)
* [http://www.vupen.com/english/advisories/2010/1191](http://www.vupen.com/english/advisories/2010/1191)
* [http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html](http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html)
* [http://www.vupen.com/english/advisories/2010/1350](http://www.vupen.com/english/advisories/2010/1350)
* [http://secunia.com/advisories/40070](http://secunia.com/advisories/40070)
* [http://osvdb.org/65202](http://osvdb.org/65202)
* [http://www.openoffice.org/security/cves/CVE-2009-3555.html](http://www.openoffice.org/security/cves/CVE-2009-3555.html)
* [http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1](http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1)
* [http://secunia.com/advisories/39127](http://secunia.com/advisories/39127)
* [http://www.vupen.com/english/advisories/2010/1639](http://www.vupen.com/english/advisories/2010/1639)
* [http://www.opera.com/support/search/view/944/](http://www.opera.com/support/search/view/944/)
* [http://www.ubuntu.com/usn/USN-927-5](http://www.ubuntu.com/usn/USN-927-5)
* [http://www.vupen.com/english/advisories/2010/1673](http://www.vupen.com/english/advisories/2010/1673)
* [http://www.opera.com/docs/changelogs/unix/1060/](http://www.opera.com/docs/changelogs/unix/1060/)
* [http://www.ubuntu.com/usn/USN-927-4](http://www.ubuntu.com/usn/USN-927-4)
* [http://www.vupen.com/english/advisories/2010/1793](http://www.vupen.com/english/advisories/2010/1793)
* [http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751](http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751)
* [http://secunia.com/advisories/40545](http://secunia.com/advisories/40545)
* [http://secunia.com/advisories/40747](http://secunia.com/advisories/40747)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041)
* [http://www.vupen.com/english/advisories/2010/2010](http://www.vupen.com/english/advisories/2010/2010)
* [http://secunia.com/advisories/40866](http://secunia.com/advisories/40866)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054](http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21432298](http://www-01.ibm.com/support/docview.wss?uid=swg21432298)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055](http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055)
* [http://www.us-cert.gov/cas/techalerts/TA10-222A.html](http://www.us-cert.gov/cas/techalerts/TA10-222A.html)
* [http://secunia.com/advisories/41490](http://secunia.com/advisories/41490)
* [http://secunia.com/advisories/41480](http://secunia.com/advisories/41480)
* [http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995](http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995)
* [http://www.vupen.com/english/advisories/2010/2745](http://www.vupen.com/english/advisories/2010/2745)
* [http://support.avaya.com/css/P8/documents/100114315](http://support.avaya.com/css/P8/documents/100114315)
* [http://support.avaya.com/css/P8/documents/100114327](http://support.avaya.com/css/P8/documents/100114327)
* [http://www.redhat.com/support/errata/RHSA-2010-0770.html](http://www.redhat.com/support/errata/RHSA-2010-0770.html)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html)
* [http://www.us-cert.gov/cas/techalerts/TA10-287A.html](http://www.us-cert.gov/cas/techalerts/TA10-287A.html)
* [http://www.ubuntu.com/usn/USN-1010-1](http://www.ubuntu.com/usn/USN-1010-1)
* [http://www.redhat.com/support/errata/RHSA-2010-0786.html](http://www.redhat.com/support/errata/RHSA-2010-0786.html)
* [http://secunia.com/advisories/41972](http://secunia.com/advisories/41972)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html)
* [http://www.redhat.com/support/errata/RHSA-2010-0807.html](http://www.redhat.com/support/errata/RHSA-2010-0807.html)
* [http://secunia.com/advisories/41967](http://secunia.com/advisories/41967)
* [http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html](http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html)
* [http://www.redhat.com/support/errata/RHSA-2010-0865.html](http://www.redhat.com/support/errata/RHSA-2010-0865.html)
* [http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html](http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html)
* [http://www.redhat.com/support/errata/RHSA-2010-0768.html](http://www.redhat.com/support/errata/RHSA-2010-0768.html)
* [http://www.vupen.com/english/advisories/2010/3086](http://www.vupen.com/english/advisories/2010/3086)
* [http://www-01.ibm.com/support/docview.wss?uid=swg24006386](http://www-01.ibm.com/support/docview.wss?uid=swg24006386)
* [http://secunia.com/advisories/42379](http://secunia.com/advisories/42379)
* [http://secunia.com/advisories/42377](http://secunia.com/advisories/42377)
* [http://www.securitytracker.com/id?1024789](http://www.securitytracker.com/id?1024789)
* [http://secunia.com/advisories/42467](http://secunia.com/advisories/42467)
* [http://www.vupen.com/english/advisories/2010/3126](http://www.vupen.com/english/advisories/2010/3126)
* [http://www.vmware.com/security/advisories/VMSA-2010-0019.html](http://www.vmware.com/security/advisories/VMSA-2010-0019.html)
* [http://www.vupen.com/english/advisories/2010/3069](http://www.vupen.com/english/advisories/2010/3069)
* [http://secunia.com/advisories/42811](http://secunia.com/advisories/42811)
* [http://www.vupen.com/english/advisories/2011/0032](http://www.vupen.com/english/advisories/2011/0032)
* [http://www.debian.org/security/2011/dsa-2141](http://www.debian.org/security/2011/dsa-2141)
* [http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html](http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html)
* [http://www.redhat.com/support/errata/RHSA-2010-0986.html](http://www.redhat.com/support/errata/RHSA-2010-0986.html)
* [http://www.redhat.com/support/errata/RHSA-2010-0987.html](http://www.redhat.com/support/errata/RHSA-2010-0987.html)
* [http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html)
* [http://secunia.com/advisories/42724](http://secunia.com/advisories/42724)
* [http://secunia.com/advisories/42816](http://secunia.com/advisories/42816)
* [http://secunia.com/advisories/42808](http://secunia.com/advisories/42808)
* [http://secunia.com/advisories/42733](http://secunia.com/advisories/42733)
* [https://kb.bluecoat.com/index?page=content&id=SA50](https://kb.bluecoat.com/index?page=content&id=SA50)
* [http://www.vupen.com/english/advisories/2011/0033](http://www.vupen.com/english/advisories/2011/0033)
* [http://www.vupen.com/english/advisories/2011/0086](http://www.vupen.com/english/advisories/2011/0086)
* [http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html)
* [http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html](http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html)
* [http://secunia.com/advisories/43308](http://secunia.com/advisories/43308)
* [http://www.vmware.com/security/advisories/VMSA-2011-0003.html](http://www.vmware.com/security/advisories/VMSA-2011-0003.html)
* [http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html](http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html)
* [http://secunia.com/advisories/44183](http://secunia.com/advisories/44183)
* [http://www.redhat.com/support/errata/RHSA-2011-0880.html](http://www.redhat.com/support/errata/RHSA-2011-0880.html)
* [http://marc.info/?l=bugtraq&m=130497311408250&w=2](http://marc.info/?l=bugtraq&m=130497311408250&w=2)
* [http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html](http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html)
* [http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html](http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html)
* [http://marc.info/?l=bugtraq&m=132077688910227&w=2](http://marc.info/?l=bugtraq&m=132077688910227&w=2)
* [http://secunia.com/advisories/44954](http://secunia.com/advisories/44954)
* [http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html](http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html)
* [http://www.securityfocus.com/archive/1/522176](http://www.securityfocus.com/archive/1/522176)
* [http://security.gentoo.org/glsa/glsa-201203-22.xml](http://security.gentoo.org/glsa/glsa-201203-22.xml)
* [http://secunia.com/advisories/48577](http://secunia.com/advisories/48577)
* [http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html](http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html)
* [http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html](http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html)
* [http://security.gentoo.org/glsa/glsa-201406-32.xml](http://security.gentoo.org/glsa/glsa-201406-32.xml)
* [http://www.openssl.org/news/secadv_20091111.txt](http://www.openssl.org/news/secadv_20091111.txt)
* [http://secunia.com/advisories/41818](http://secunia.com/advisories/41818)
* [http://marc.info/?l=bugtraq&m=142660345230545&w=2](http://marc.info/?l=bugtraq&m=142660345230545&w=2)
* [http://www.debian.org/security/2015/dsa-3253](http://www.debian.org/security/2015/dsa-3253)
* [https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888](https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888)
* [http://marc.info/?l=bugtraq&m=127128920008563&w=2](http://marc.info/?l=bugtraq&m=127128920008563&w=2)
* [http://marc.info/?l=bugtraq&m=134254866602253&w=2](http://marc.info/?l=bugtraq&m=134254866602253&w=2)
* [http://marc.info/?l=bugtraq&m=127557596201693&w=2](http://marc.info/?l=bugtraq&m=127557596201693&w=2)
* [http://marc.info/?l=bugtraq&m=126150535619567&w=2](http://marc.info/?l=bugtraq&m=126150535619567&w=2)
* [http://marc.info/?l=bugtraq&m=133469267822771&w=2](http://marc.info/?l=bugtraq&m=133469267822771&w=2)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/54158](https://exchange.xforce.ibmcloud.com/vulnerabilities/54158)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088)
* [http://www.securityfocus.com/archive/1/516397/100/0/threaded](http://www.securityfocus.com/archive/1/516397/100/0/threaded)
* [http://www.securityfocus.com/archive/1/515055/100/0/threaded](http://www.securityfocus.com/archive/1/515055/100/0/threaded)
* [http://www.securityfocus.com/archive/1/508130/100/0/threaded](http://www.securityfocus.com/archive/1/508130/100/0/threaded)
* [http://www.securityfocus.com/archive/1/508075/100/0/threaded](http://www.securityfocus.com/archive/1/508075/100/0/threaded)
* [http://www.securityfocus.com/archive/1/507952/100/0/threaded](http://www.securityfocus.com/archive/1/507952/100/0/threaded)
* [https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049](https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049)
* [https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E](https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E)
* [https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E](https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E)
* [https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E](https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E)
* [https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E](https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E) -
Moyenne CVE-2009-3560 Signalée 04/12/2009The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720.
* [http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1](http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1)
* [http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165](http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?r1=1.164&r2=1.165)
* [https://bugzilla.redhat.com/show_bug.cgi?id=533174](https://bugzilla.redhat.com/show_bug.cgi?id=533174)
* [http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?view=log#rev1.165](http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmlparse.c?view=log#rev1.165)
* [http://www.securityfocus.com/bid/37203](http://www.securityfocus.com/bid/37203)
* [http://mail.python.org/pipermail/expat-bugs/2009-November/002846.html](http://mail.python.org/pipermail/expat-bugs/2009-November/002846.html)
* [http://secunia.com/advisories/37537](http://secunia.com/advisories/37537)
* [http://www.securitytracker.com/id?1023278](http://www.securitytracker.com/id?1023278)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:316](http://www.mandriva.com/security/advisories?name=MDVSA-2009:316)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00394.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00394.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00413.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00413.html)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00370.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00370.html)
* [http://www.debian.org/security/2009/dsa-1953](http://www.debian.org/security/2009/dsa-1953)
* [http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html](http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00007.html)
* [http://www.ubuntu.com/usn/USN-890-1](http://www.ubuntu.com/usn/USN-890-1)
* [http://secunia.com/advisories/38231](http://secunia.com/advisories/38231)
* [http://secunia.com/advisories/38834](http://secunia.com/advisories/38834)
* [http://lists.vmware.com/pipermail/security-announce/2010/000082.html](http://lists.vmware.com/pipermail/security-announce/2010/000082.html)
* [http://secunia.com/advisories/38794](http://secunia.com/advisories/38794)
* [http://secunia.com/advisories/38832](http://secunia.com/advisories/38832)
* [http://www.vupen.com/english/advisories/2010/0528](http://www.vupen.com/english/advisories/2010/0528)
* [http://www.ubuntu.com/usn/USN-890-6](http://www.ubuntu.com/usn/USN-890-6)
* [http://secunia.com/advisories/39478](http://secunia.com/advisories/39478)
* [http://www.vupen.com/english/advisories/2010/0896](http://www.vupen.com/english/advisories/2010/0896)
* [http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html)
* [http://www.vupen.com/english/advisories/2010/1107](http://www.vupen.com/english/advisories/2010/1107)
* [http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html](http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html)
* [http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html)
* [http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html)
* [http://secunia.com/advisories/41701](http://secunia.com/advisories/41701)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026](http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026)
* [http://www.vupen.com/english/advisories/2011/0359](http://www.vupen.com/english/advisories/2011/0359)
* [http://secunia.com/advisories/43300](http://secunia.com/advisories/43300)
* [http://www.redhat.com/support/errata/RHSA-2011-0896.html](http://www.redhat.com/support/errata/RHSA-2011-0896.html)
* [http://marc.info/?l=bugtraq&m=130168502603566&w=2](http://marc.info/?l=bugtraq&m=130168502603566&w=2)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6883](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6883)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12942](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12942)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10613](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10613)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2009-3720 Signalée 03/11/2009The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.
* [http://www.openwall.com/lists/oss-security/2009/08/26/4](http://www.openwall.com/lists/oss-security/2009/08/26/4)
* [https://bugs.gentoo.org/show_bug.cgi?id=280615](https://bugs.gentoo.org/show_bug.cgi?id=280615)
* [http://www.openwall.com/lists/oss-security/2009/08/21/2](http://www.openwall.com/lists/oss-security/2009/08/21/2)
* [http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patch](http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?r1=1.13&r2=1.15&view=patch)
* [http://mail.python.org/pipermail/expat-bugs/2009-January/002781.html](http://mail.python.org/pipermail/expat-bugs/2009-January/002781.html)
* [http://www.openwall.com/lists/oss-security/2009/10/23/2](http://www.openwall.com/lists/oss-security/2009/10/23/2)
* [http://sourceforge.net/tracker/index.php?func=detail&aid=1990430&group_id=10127&atid=110127](http://sourceforge.net/tracker/index.php?func=detail&aid=1990430&group_id=10127&atid=110127)
* [http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?view=log](http://expat.cvs.sourceforge.net/viewvc/expat/expat/lib/xmltok_impl.c?view=log)
* [http://www.openwall.com/lists/oss-security/2009/10/26/3](http://www.openwall.com/lists/oss-security/2009/10/26/3)
* [http://www.openwall.com/lists/oss-security/2009/08/27/6](http://www.openwall.com/lists/oss-security/2009/08/27/6)
* [http://www.openwall.com/lists/oss-security/2009/09/06/1](http://www.openwall.com/lists/oss-security/2009/09/06/1)
* [http://www.openwall.com/lists/oss-security/2009/08/26/3](http://www.openwall.com/lists/oss-security/2009/08/26/3)
* [http://svn.python.org/view?view=rev&revision=74429](http://svn.python.org/view?view=rev&revision=74429)
* [http://www.openwall.com/lists/oss-security/2009/10/23/6](http://www.openwall.com/lists/oss-security/2009/10/23/6)
* [http://www.openwall.com/lists/oss-security/2009/10/22/9](http://www.openwall.com/lists/oss-security/2009/10/22/9)
* [http://www.openwall.com/lists/oss-security/2009/10/28/3](http://www.openwall.com/lists/oss-security/2009/10/28/3)
* [http://www.openwall.com/lists/oss-security/2009/10/22/5](http://www.openwall.com/lists/oss-security/2009/10/22/5)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:211](http://www.mandriva.com/security/advisories?name=MDVSA-2009:211)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:217](http://www.mandriva.com/security/advisories?name=MDVSA-2009:217)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:218](http://www.mandriva.com/security/advisories?name=MDVSA-2009:218)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:215](http://www.mandriva.com/security/advisories?name=MDVSA-2009:215)
* [http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html](http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00004.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:212](http://www.mandriva.com/security/advisories?name=MDVSA-2009:212)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:220](http://www.mandriva.com/security/advisories?name=MDVSA-2009:220)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:216](http://www.mandriva.com/security/advisories?name=MDVSA-2009:216)
* [https://bugzilla.redhat.com/show_bug.cgi?id=531697](https://bugzilla.redhat.com/show_bug.cgi?id=531697)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00413.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00413.html)
* [http://secunia.com/advisories/37324](http://secunia.com/advisories/37324)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2009:219](http://www.mandriva.com/security/advisories?name=MDVSA-2009:219)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00370.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00370.html)
* [http://secunia.com/advisories/37537](http://secunia.com/advisories/37537)
* [http://www.securitytracker.com/id?1023160](http://www.securitytracker.com/id?1023160)
* [http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1](http://sunsolve.sun.com/search/document.do?assetkey=1-66-273630-1)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01274.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01274.html)
* [http://secunia.com/advisories/37925](http://secunia.com/advisories/37925)
* [http://www.ubuntu.com/usn/USN-890-1](http://www.ubuntu.com/usn/USN-890-1)
* [http://secunia.com/advisories/38231](http://secunia.com/advisories/38231)
* [http://secunia.com/advisories/38834](http://secunia.com/advisories/38834)
* [http://www.vupen.com/english/advisories/2010/0528](http://www.vupen.com/english/advisories/2010/0528)
* [http://secunia.com/advisories/38794](http://secunia.com/advisories/38794)
* [http://secunia.com/advisories/38832](http://secunia.com/advisories/38832)
* [http://lists.vmware.com/pipermail/security-announce/2010/000082.html](http://lists.vmware.com/pipermail/security-announce/2010/000082.html)
* [http://www.ubuntu.com/usn/USN-890-6](http://www.ubuntu.com/usn/USN-890-6)
* [http://secunia.com/advisories/39478](http://secunia.com/advisories/39478)
* [http://www.vupen.com/english/advisories/2010/0896](http://www.vupen.com/english/advisories/2010/0896)
* [http://www.vupen.com/english/advisories/2010/1107](http://www.vupen.com/english/advisories/2010/1107)
* [http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html)
* [http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html](http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html)
* [http://secunia.com/advisories/38050](http://secunia.com/advisories/38050)
* [http://www.redhat.com/support/errata/RHSA-2010-0002.html](http://www.redhat.com/support/errata/RHSA-2010-0002.html)
* [http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html)
* [http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html](http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html)
* [http://secunia.com/advisories/41701](http://secunia.com/advisories/41701)
* [http://www.vupen.com/english/advisories/2011/0359](http://www.vupen.com/english/advisories/2011/0359)
* [http://secunia.com/advisories/43300](http://secunia.com/advisories/43300)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026](http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026)
* [http://www.redhat.com/support/errata/RHSA-2011-0896.html](http://www.redhat.com/support/errata/RHSA-2011-0896.html)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051367.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051367.html)
* [http://secunia.com/advisories/42326](http://secunia.com/advisories/42326)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051228.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051228.html)
* [http://www.vupen.com/english/advisories/2010/3061](http://www.vupen.com/english/advisories/2010/3061)
* [http://www.vupen.com/english/advisories/2010/3053](http://www.vupen.com/english/advisories/2010/3053)
* [http://www.vupen.com/english/advisories/2010/3035](http://www.vupen.com/english/advisories/2010/3035)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051405.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051405.html)
* [http://secunia.com/advisories/42338](http://secunia.com/advisories/42338)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051442.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051442.html)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051247.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-November/051247.html)
* [http://marc.info/?l=bugtraq&m=130168502603566&w=2](http://marc.info/?l=bugtraq&m=130168502603566&w=2)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7112](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7112)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12719](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12719)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11019](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11019)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2010-0408 Signalée 05/03/2010The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
* [http://www.mandriva.com/security/advisories?name=MDVSA-2010:053](http://www.mandriva.com/security/advisories?name=MDVSA-2010:053)
* [http://svn.apache.org/viewvc?view=revision&revision=917876](http://svn.apache.org/viewvc?view=revision&revision=917876)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/modules/proxy/mod_proxy_ajp.c?r1=917876&r2=917875&pathrev=917876](http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/modules/proxy/mod_proxy_ajp.c?r1=917876&r2=917875&pathrev=917876)
* [https://bugzilla.redhat.com/show_bug.cgi?id=569905](https://bugzilla.redhat.com/show_bug.cgi?id=569905)
* [http://www.securityfocus.com/bid/38491](http://www.securityfocus.com/bid/38491)
* [http://www.redhat.com/support/errata/RHSA-2010-0168.html](http://www.redhat.com/support/errata/RHSA-2010-0168.html)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247](http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247)
* [http://secunia.com/advisories/39628](http://secunia.com/advisories/39628)
* [http://www.vupen.com/english/advisories/2010/1001](http://www.vupen.com/english/advisories/2010/1001)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html)
* [http://www.debian.org/security/2010/dsa-2035](http://www.debian.org/security/2010/dsa-2035)
* [http://www.vupen.com/english/advisories/2010/1057](http://www.vupen.com/english/advisories/2010/1057)
* [http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html)
* [http://secunia.com/advisories/39656](http://secunia.com/advisories/39656)
* [http://www.vupen.com/english/advisories/2010/0911](http://www.vupen.com/english/advisories/2010/0911)
* [http://secunia.com/advisories/39501](http://secunia.com/advisories/39501)
* [http://secunia.com/advisories/39632](http://secunia.com/advisories/39632)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html)
* [http://www.vupen.com/english/advisories/2010/0994](http://www.vupen.com/english/advisories/2010/0994)
* [http://secunia.com/advisories/40096](http://secunia.com/advisories/40096)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM08939](http://www-01.ibm.com/support/docview.wss?uid=swg1PM08939)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829](http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829)
* [http://www.vupen.com/english/advisories/2010/1411](http://www.vupen.com/english/advisories/2010/1411)
* [http://secunia.com/advisories/39100](http://secunia.com/advisories/39100)
* [http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html](http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html)
* [http://support.apple.com/kb/HT4435](http://support.apple.com/kb/HT4435)
* [http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html](http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [http://marc.info/?l=bugtraq&m=127557640302499&w=2](http://marc.info/?l=bugtraq&m=127557640302499&w=2)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9935](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9935)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8619](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8619)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2010-0434 Signalée 05/03/2010The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
* [http://svn.apache.org/viewvc?view=revision&revision=918427](http://svn.apache.org/viewvc?view=revision&revision=918427)
* [https://bugzilla.redhat.com/show_bug.cgi?id=570171](https://bugzilla.redhat.com/show_bug.cgi?id=570171)
* [http://www.securityfocus.com/bid/38494](http://www.securityfocus.com/bid/38494)
* [http://svn.apache.org/viewvc?view=revision&revision=917867](http://svn.apache.org/viewvc?view=revision&revision=917867)
* [https://issues.apache.org/bugzilla/show_bug.cgi?id=48359](https://issues.apache.org/bugzilla/show_bug.cgi?id=48359)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/server/protocol.c?r1=917617&r2=917867&pathrev=917867&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/branches/2.2.x/server/protocol.c?r1=917617&r2=917867&pathrev=917867&diff_format=h)
* [http://www.redhat.com/support/errata/RHSA-2010-0168.html](http://www.redhat.com/support/errata/RHSA-2010-0168.html)
* [http://www.redhat.com/support/errata/RHSA-2010-0175.html](http://www.redhat.com/support/errata/RHSA-2010-0175.html)
* [http://secunia.com/advisories/39628](http://secunia.com/advisories/39628)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247](http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247)
* [http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.html)
* [http://secunia.com/advisories/39501](http://secunia.com/advisories/39501)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html)
* [http://www.vupen.com/english/advisories/2010/1057](http://www.vupen.com/english/advisories/2010/1057)
* [http://secunia.com/advisories/39632](http://secunia.com/advisories/39632)
* [http://www.vupen.com/english/advisories/2010/0911](http://www.vupen.com/english/advisories/2010/0911)
* [http://www.vupen.com/english/advisories/2010/0994](http://www.vupen.com/english/advisories/2010/0994)
* [http://www.debian.org/security/2010/dsa-2035](http://www.debian.org/security/2010/dsa-2035)
* [http://www.vupen.com/english/advisories/2010/1001](http://www.vupen.com/english/advisories/2010/1001)
* [http://secunia.com/advisories/39656](http://secunia.com/advisories/39656)
* [http://secunia.com/advisories/40096](http://secunia.com/advisories/40096)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829](http://www-01.ibm.com/support/docview.wss?uid=swg1PM15829)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM08939](http://www-01.ibm.com/support/docview.wss?uid=swg1PM08939)
* [http://www.vupen.com/english/advisories/2010/1411](http://www.vupen.com/english/advisories/2010/1411)
* [http://secunia.com/advisories/39100](http://secunia.com/advisories/39100)
* [http://secunia.com/advisories/39115](http://secunia.com/advisories/39115)
* [http://lists.vmware.com/pipermail/security-announce/2010/000105.html](http://lists.vmware.com/pipermail/security-announce/2010/000105.html)
* [http://www.vmware.com/security/advisories/VMSA-2010-0014.html](http://www.vmware.com/security/advisories/VMSA-2010-0014.html)
* [http://support.apple.com/kb/HT4435](http://support.apple.com/kb/HT4435)
* [http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html](http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [http://marc.info/?l=bugtraq&m=127557640302499&w=2](http://marc.info/?l=bugtraq&m=127557640302499&w=2)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/56625](https://exchange.xforce.ibmcloud.com/vulnerabilities/56625)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8695](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8695)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10358](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10358)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2010-1452 Signalée 28/07/2010The (1) mod_cache and (2) mod_dav modules in the Apache HTTP Server 2.2.x before 2.2.16 allow remote attackers to cause a denial of service (process crash) via a request that lacks a path.
* [https://issues.apache.org/bugzilla/show_bug.cgi?id=49246](https://issues.apache.org/bugzilla/show_bug.cgi?id=49246)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://marc.info/?l=apache-announce&m=128009718610929&w=2](http://marc.info/?l=apache-announce&m=128009718610929&w=2)
* [http://www.redhat.com/support/errata/RHSA-2010-0659.html](http://www.redhat.com/support/errata/RHSA-2010-0659.html)
* [http://www.vupen.com/english/advisories/2010/2218](http://www.vupen.com/english/advisories/2010/2218)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.467395](http://slackware.com/security/viewer.php?l=slackware-security&y=2010&m=slackware-security.467395)
* [http://ubuntu.com/usn/usn-1021-1](http://ubuntu.com/usn/usn-1021-1)
* [http://secunia.com/advisories/42367](http://secunia.com/advisories/42367)
* [http://www.vupen.com/english/advisories/2010/3064](http://www.vupen.com/english/advisories/2010/3064)
* [http://marc.info/?l=bugtraq&m=129190899612998&w=2](http://marc.info/?l=bugtraq&m=129190899612998&w=2)
* [http://www.vupen.com/english/advisories/2011/0291](http://www.vupen.com/english/advisories/2011/0291)
* [http://blogs.sun.com/security/entry/cve_2010_1452_mod_dav](http://blogs.sun.com/security/entry/cve_2010_1452_mod_dav)
* [http://support.apple.com/kb/HT4581](http://support.apple.com/kb/HT4581)
* [http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html](http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html)
* [http://www.redhat.com/support/errata/RHSA-2011-0897.html](http://www.redhat.com/support/errata/RHSA-2011-0897.html)
* [http://www.redhat.com/support/errata/RHSA-2011-0896.html](http://www.redhat.com/support/errata/RHSA-2011-0896.html)
* [http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html](http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00009.html)
* [http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.html](http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00008.html)
* [http://marc.info/?l=bugtraq&m=133355494609819&w=2](http://marc.info/?l=bugtraq&m=133355494609819&w=2)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12341](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12341)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11683](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11683)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2010-1623 Signalée 04/10/2010Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
* [http://security-tracker.debian.org/tracker/CVE-2010-1623](http://security-tracker.debian.org/tracker/CVE-2010-1623)
* [http://svn.apache.org/viewvc?view=revision&revision=1003495](http://svn.apache.org/viewvc?view=revision&revision=1003495)
* [http://svn.apache.org/viewvc?view=revision&revision=1003492](http://svn.apache.org/viewvc?view=revision&revision=1003492)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2010:192](http://www.mandriva.com/security/advisories?name=MDVSA-2010:192)
* [http://www.vupen.com/english/advisories/2010/2556](http://www.vupen.com/english/advisories/2010/2556)
* [http://svn.apache.org/viewvc?view=revision&revision=1003494](http://svn.apache.org/viewvc?view=revision&revision=1003494)
* [http://svn.apache.org/viewvc?view=revision&revision=1003493](http://svn.apache.org/viewvc?view=revision&revision=1003493)
* [http://www.vupen.com/english/advisories/2010/2557](http://www.vupen.com/english/advisories/2010/2557)
* [http://svn.apache.org/viewvc?view=revision&revision=1003626](http://svn.apache.org/viewvc?view=revision&revision=1003626)
* [http://www.securityfocus.com/bid/43673](http://www.securityfocus.com/bid/43673)
* [http://secunia.com/advisories/41701](http://secunia.com/advisories/41701)
* [http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3](http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049885.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049885.html)
* [http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049939.html](http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049939.html)
* [http://www.vupen.com/english/advisories/2010/2806](http://www.vupen.com/english/advisories/2010/2806)
* [http://secunia.com/advisories/42015](http://secunia.com/advisories/42015)
* [http://secunia.com/advisories/42361](http://secunia.com/advisories/42361)
* [http://ubuntu.com/usn/usn-1021-1](http://ubuntu.com/usn/usn-1021-1)
* [http://blogs.sun.com/security/entry/cve_2010_1623_memory_leak](http://blogs.sun.com/security/entry/cve_2010_1623_memory_leak)
* [http://secunia.com/advisories/42403](http://secunia.com/advisories/42403)
* [http://secunia.com/advisories/42367](http://secunia.com/advisories/42367)
* [http://www.ubuntu.com/usn/USN-1022-1](http://www.ubuntu.com/usn/USN-1022-1)
* [http://www.vupen.com/english/advisories/2010/3074](http://www.vupen.com/english/advisories/2010/3074)
* [http://secunia.com/advisories/42537](http://secunia.com/advisories/42537)
* [http://www.vupen.com/english/advisories/2010/3065](http://www.vupen.com/english/advisories/2010/3065)
* [http://www.redhat.com/support/errata/RHSA-2010-0950.html](http://www.redhat.com/support/errata/RHSA-2010-0950.html)
* [http://www.vupen.com/english/advisories/2010/3064](http://www.vupen.com/english/advisories/2010/3064)
* [http://www.vupen.com/english/advisories/2011/0358](http://www.vupen.com/english/advisories/2011/0358)
* [http://secunia.com/advisories/43285](http://secunia.com/advisories/43285)
* [http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.627828](http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.627828)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM31601](http://www-01.ibm.com/support/docview.wss?uid=swg1PM31601)
* [http://secunia.com/advisories/43211](http://secunia.com/advisories/43211)
* [http://www.redhat.com/support/errata/RHSA-2011-0897.html](http://www.redhat.com/support/errata/RHSA-2011-0897.html)
* [http://www.redhat.com/support/errata/RHSA-2011-0896.html](http://www.redhat.com/support/errata/RHSA-2011-0896.html)
* [http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html](http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html)
* [http://marc.info/?l=bugtraq&m=130168502603566&w=2](http://marc.info/?l=bugtraq&m=130168502603566&w=2)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12800](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12800)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2011-0419 Signalée 16/05/2011Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.
* [http://cxib.net/stuff/apr_fnmatch.txts](http://cxib.net/stuff/apr_fnmatch.txts)
* [http://securityreason.com/achievement_securityalert/98](http://securityreason.com/achievement_securityalert/98)
* [http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fnmatch.c#rev1.15](http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fnmatch.c#rev1.15)
* [http://www.apache.org/dist/apr/CHANGES-APR-1.4](http://www.apache.org/dist/apr/CHANGES-APR-1.4)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://svn.apache.org/viewvc?view=revision&revision=1098188](http://svn.apache.org/viewvc?view=revision&revision=1098188)
* [http://secunia.com/advisories/44490](http://secunia.com/advisories/44490)
* [http://www.redhat.com/support/errata/RHSA-2011-0507.html](http://www.redhat.com/support/errata/RHSA-2011-0507.html)
* [http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gen/fnmatch.c#rev1.22](http://cvsweb.netbsd.org/bsdweb.cgi/src/lib/libc/gen/fnmatch.c#rev1.22)
* [http://www.apache.org/dist/apr/Announcement1.x.html](http://www.apache.org/dist/apr/Announcement1.x.html)
* [http://securitytracker.com/id?1025527](http://securitytracker.com/id?1025527)
* [http://www.apache.org/dist/httpd/Announcement2.2.html](http://www.apache.org/dist/httpd/Announcement2.2.html)
* [http://secunia.com/advisories/44564](http://secunia.com/advisories/44564)
* [https://bugzilla.redhat.com/show_bug.cgi?id=703390](https://bugzilla.redhat.com/show_bug.cgi?id=703390)
* [http://cxib.net/stuff/apache.fnmatch.phps](http://cxib.net/stuff/apache.fnmatch.phps)
* [http://svn.apache.org/viewvc/apr/apr/branches/1.4.x/strings/apr_fnmatch.c?r1=731029&r2=1098902](http://svn.apache.org/viewvc/apr/apr/branches/1.4.x/strings/apr_fnmatch.c?r1=731029&r2=1098902)
* [http://svn.apache.org/viewvc?view=revision&revision=1098799](http://svn.apache.org/viewvc?view=revision&revision=1098799)
* [http://secunia.com/advisories/44574](http://secunia.com/advisories/44574)
* [http://www.debian.org/security/2011/dsa-2237](http://www.debian.org/security/2011/dsa-2237)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2011:084](http://www.mandriva.com/security/advisories?name=MDVSA-2011:084)
* [http://www.redhat.com/support/errata/RHSA-2011-0897.html](http://www.redhat.com/support/errata/RHSA-2011-0897.html)
* [http://www.redhat.com/support/errata/RHSA-2011-0896.html](http://www.redhat.com/support/errata/RHSA-2011-0896.html)
* [http://securityreason.com/securityalert/8246](http://securityreason.com/securityalert/8246)
* [http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html](http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html)
* [http://support.apple.com/kb/HT5002](http://support.apple.com/kb/HT5002)
* [http://marc.info/?l=bugtraq&m=131551295528105&w=2](http://marc.info/?l=bugtraq&m=131551295528105&w=2)
* [http://marc.info/?l=bugtraq&m=131731002122529&w=2](http://marc.info/?l=bugtraq&m=131731002122529&w=2)
* [http://marc.info/?l=bugtraq&m=132033751509019&w=2](http://marc.info/?l=bugtraq&m=132033751509019&w=2)
* [http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html](http://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.html)
* [http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html](http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html)
* [http://marc.info/?l=bugtraq&m=134987041210674&w=2](http://marc.info/?l=bugtraq&m=134987041210674&w=2)
* [http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html](http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14804](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14804)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14638](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14638)
* [http://secunia.com/advisories/48308](http://secunia.com/advisories/48308)
* [http://www.mail-archive.com/dev%40apr.apache.org/msg23976.html](http://www.mail-archive.com/dev%40apr.apache.org/msg23976.html)
* [http://www.mail-archive.com/dev%40apr.apache.org/msg23961.html](http://www.mail-archive.com/dev%40apr.apache.org/msg23961.html)
* [http://www.mail-archive.com/dev%40apr.apache.org/msg23960.html](http://www.mail-archive.com/dev%40apr.apache.org/msg23960.html)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r064df0985779b7ee044d3120d71ba59750427cf53f57ba3384e3773f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r064df0985779b7ee044d3120d71ba59750427cf53f57ba3384e3773f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2012-0031 Signalée 18/01/2012scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
* [https://bugzilla.redhat.com/show_bug.cgi?id=773744](https://bugzilla.redhat.com/show_bug.cgi?id=773744)
* [http://www.halfdog.net/Security/2011/ApacheScoreboardInvalidFreeOnShutdown/](http://www.halfdog.net/Security/2011/ApacheScoreboardInvalidFreeOnShutdown/)
* [http://svn.apache.org/viewvc?view=revision&revision=1230065](http://svn.apache.org/viewvc?view=revision&revision=1230065)
* [http://secunia.com/advisories/47410](http://secunia.com/advisories/47410)
* [http://www.securityfocus.com/bid/51407](http://www.securityfocus.com/bid/51407)
* [http://rhn.redhat.com/errata/RHSA-2012-0128.html](http://rhn.redhat.com/errata/RHSA-2012-0128.html)
* [http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html](http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041)
* [http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html](http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html)
* [http://secunia.com/advisories/48551](http://secunia.com/advisories/48551)
* [http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html](http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html)
* [http://support.apple.com/kb/HT5501](http://support.apple.com/kb/HT5501)
* [http://marc.info/?l=bugtraq&m=134987041210674&w=2](http://marc.info/?l=bugtraq&m=134987041210674&w=2)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [http://marc.info/?l=bugtraq&m=133494237717847&w=2](http://marc.info/?l=bugtraq&m=133494237717847&w=2)
* [http://www.debian.org/security/2012/dsa-2405](http://www.debian.org/security/2012/dsa-2405)
* [http://rhn.redhat.com/errata/RHSA-2012-0543.html](http://rhn.redhat.com/errata/RHSA-2012-0543.html)
* [http://rhn.redhat.com/errata/RHSA-2012-0542.html](http://rhn.redhat.com/errata/RHSA-2012-0542.html)
* [http://marc.info/?l=bugtraq&m=133294460209056&w=2](http://marc.info/?l=bugtraq&m=133294460209056&w=2)
* [http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html](http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2012:012](http://www.mandriva.com/security/advisories?name=MDVSA-2012:012)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2012-0053 Signalée 28/01/2012protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [https://bugzilla.redhat.com/show_bug.cgi?id=785069](https://bugzilla.redhat.com/show_bug.cgi?id=785069)
* [http://svn.apache.org/viewvc?view=revision&revision=1235454](http://svn.apache.org/viewvc?view=revision&revision=1235454)
* [http://www.securityfocus.com/bid/51706](http://www.securityfocus.com/bid/51706)
* [http://rhn.redhat.com/errata/RHSA-2012-0128.html](http://rhn.redhat.com/errata/RHSA-2012-0128.html)
* [http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html](http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html)
* [http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041](http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041)
* [http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html](http://www.oracle.com/technetwork/topics/security/cpujul2012-392727.html)
* [http://secunia.com/advisories/48551](http://secunia.com/advisories/48551)
* [http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html](http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html)
* [http://support.apple.com/kb/HT5501](http://support.apple.com/kb/HT5501)
* [http://marc.info/?l=bugtraq&m=136441204617335&w=2](http://marc.info/?l=bugtraq&m=136441204617335&w=2)
* [http://kb.juniper.net/JSA10585](http://kb.juniper.net/JSA10585)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:150](http://www.mandriva.com/security/advisories?name=MDVSA-2013:150)
* [http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html](http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html)
* [http://marc.info/?l=bugtraq&m=133494237717847&w=2](http://marc.info/?l=bugtraq&m=133494237717847&w=2)
* [http://marc.info/?l=bugtraq&m=133951357207000&w=2](http://marc.info/?l=bugtraq&m=133951357207000&w=2)
* [http://www.debian.org/security/2012/dsa-2405](http://www.debian.org/security/2012/dsa-2405)
* [http://rhn.redhat.com/errata/RHSA-2012-0543.html](http://rhn.redhat.com/errata/RHSA-2012-0543.html)
* [http://rhn.redhat.com/errata/RHSA-2012-0542.html](http://rhn.redhat.com/errata/RHSA-2012-0542.html)
* [http://marc.info/?l=bugtraq&m=133294460209056&w=2](http://marc.info/?l=bugtraq&m=133294460209056&w=2)
* [http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html](http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2012:012](http://www.mandriva.com/security/advisories?name=MDVSA-2012:012)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2012-0883 Signalée 18/04/2012envvars (aka envvars-std) in the Apache HTTP Server before 2.4.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse DSO in the current working directory during execution of apachectl.
* [http://www.apache.org/dist/httpd/Announcement2.4.html](http://www.apache.org/dist/httpd/Announcement2.4.html)
* [http://svn.apache.org/viewvc?view=revision&revision=1296428](http://svn.apache.org/viewvc?view=revision&revision=1296428)
* [http://article.gmane.org/gmane.comp.apache.devel/48158](http://article.gmane.org/gmane.comp.apache.devel/48158)
* [http://www.securitytracker.com/id?1026932](http://www.securitytracker.com/id?1026932)
* [http://marc.info/?l=bugtraq&m=134012830914727&w=2](http://marc.info/?l=bugtraq&m=134012830914727&w=2)
* [http://secunia.com/advisories/48849](http://secunia.com/advisories/48849)
* [http://lists.opensuse.org/opensuse-updates/2013-02/msg00009.html](http://lists.opensuse.org/opensuse-updates/2013-02/msg00009.html)
* [http://lists.opensuse.org/opensuse-updates/2013-02/msg00012.html](http://lists.opensuse.org/opensuse-updates/2013-02/msg00012.html)
* [http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf](http://www.xerox.com/download/security/security-bulletin/16287-4d6b7b0c81f7b/cert_XRX13-003_v1.0.pdf)
* [https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862](https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03839862)
* [http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html](http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html)
* [http://support.apple.com/kb/HT5880](http://support.apple.com/kb/HT5880)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/74901](https://exchange.xforce.ibmcloud.com/vulnerabilities/74901)
* [http://www.securityfocus.com/bid/53046](http://www.securityfocus.com/bid/53046)
* [http://www.apachelounge.com/Changelog-2.4.html](http://www.apachelounge.com/Changelog-2.4.html)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2012-3499 Signalée 26/02/2013Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/ldap/util_ldap_cache_mgr.c?r1=1209766&r2=1418752&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/ldap/util_ldap_cache_mgr.c?r1=1209766&r2=1418752&diff_format=h)
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_status.c?r1=1389564&r2=1413732&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_status.c?r1=1389564&r2=1413732&diff_format=h)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/mappers/mod_imagemap.c?r1=1398480&r2=1413732&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/mappers/mod_imagemap.c?r1=1398480&r2=1413732&diff_format=h)
* [http://httpd.apache.org/security/vulnerabilities_24.html](http://httpd.apache.org/security/vulnerabilities_24.html)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_ftp.c?r1=1404625&r2=1413732&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_ftp.c?r1=1404625&r2=1413732&diff_format=h)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_info.c?r1=1225799&r2=1413732&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_info.c?r1=1225799&r2=1413732&diff_format=h)
* [http://www.debian.org/security/2013/dsa-2637](http://www.debian.org/security/2013/dsa-2637)
* [http://rhn.redhat.com/errata/RHSA-2013-0815.html](http://rhn.redhat.com/errata/RHSA-2013-0815.html)
* [http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html](http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html)
* [http://support.apple.com/kb/HT5880](http://support.apple.com/kb/HT5880)
* [http://rhn.redhat.com/errata/RHSA-2013-1208.html](http://rhn.redhat.com/errata/RHSA-2013-1208.html)
* [http://rhn.redhat.com/errata/RHSA-2013-1209.html](http://rhn.redhat.com/errata/RHSA-2013-1209.html)
* [http://rhn.redhat.com/errata/RHSA-2013-1207.html](http://rhn.redhat.com/errata/RHSA-2013-1207.html)
* [http://secunia.com/advisories/55032](http://secunia.com/advisories/55032)
* [http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101196.html](http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101196.html)
* [http://www.securityfocus.com/bid/64758](http://www.securityfocus.com/bid/64758)
* [http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html](http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html)
* [http://marc.info/?l=bugtraq&m=136612293908376&w=2](http://marc.info/?l=bugtraq&m=136612293908376&w=2)
* [http://www.securityfocus.com/bid/58165](http://www.securityfocus.com/bid/58165)
* [http://www.fujitsu.com/global/support/software/security/products-f/interstage-201303e.html](http://www.fujitsu.com/global/support/software/security/products-f/interstage-201303e.html)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19312](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19312)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r1d201e3da31a2c8aa870c8314623caef7debd74a13d0f25205e26f15%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2012-4558 Signalée 26/02/2013Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted string.
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://httpd.apache.org/security/vulnerabilities_24.html](http://httpd.apache.org/security/vulnerabilities_24.html)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_balancer.c?r1=1404653&r2=1413732&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_balancer.c?r1=1404653&r2=1413732&diff_format=h)
* [http://www.debian.org/security/2013/dsa-2637](http://www.debian.org/security/2013/dsa-2637)
* [http://rhn.redhat.com/errata/RHSA-2013-0815.html](http://rhn.redhat.com/errata/RHSA-2013-0815.html)
* [http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html](http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html)
* [http://support.apple.com/kb/HT5880](http://support.apple.com/kb/HT5880)
* [http://rhn.redhat.com/errata/RHSA-2013-1208.html](http://rhn.redhat.com/errata/RHSA-2013-1208.html)
* [http://rhn.redhat.com/errata/RHSA-2013-1209.html](http://rhn.redhat.com/errata/RHSA-2013-1209.html)
* [http://rhn.redhat.com/errata/RHSA-2013-1207.html](http://rhn.redhat.com/errata/RHSA-2013-1207.html)
* [http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101196.html](http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101196.html)
* [http://www.securityfocus.com/bid/64758](http://www.securityfocus.com/bid/64758)
* [http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html](http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html)
* [http://marc.info/?l=bugtraq&m=136612293908376&w=2](http://marc.info/?l=bugtraq&m=136612293908376&w=2)
* [http://www.securityfocus.com/bid/58165](http://www.securityfocus.com/bid/58165)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18977](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18977)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2013-1862 Signalée 10/06/2013mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
* [http://people.apache.org/~jorton/mod_rewrite-CVE-2013-1862.patch](http://people.apache.org/~jorton/mod_rewrite-CVE-2013-1862.patch)
* [http://svn.apache.org/viewvc?view=revision&revision=r1469311](http://svn.apache.org/viewvc?view=revision&revision=r1469311)
* [https://bugzilla.redhat.com/show_bug.cgi?id=953729](https://bugzilla.redhat.com/show_bug.cgi?id=953729)
* [http://rhn.redhat.com/errata/RHSA-2013-0815.html](http://rhn.redhat.com/errata/RHSA-2013-0815.html)
* [http://lists.opensuse.org/opensuse-updates/2013-08/msg00026.html](http://lists.opensuse.org/opensuse-updates/2013-08/msg00026.html)
* [http://www.ubuntu.com/usn/USN-1903-1](http://www.ubuntu.com/usn/USN-1903-1)
* [http://lists.opensuse.org/opensuse-updates/2013-08/msg00029.html](http://lists.opensuse.org/opensuse-updates/2013-08/msg00029.html)
* [http://lists.opensuse.org/opensuse-updates/2013-08/msg00030.html](http://lists.opensuse.org/opensuse-updates/2013-08/msg00030.html)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21644047](http://www-01.ibm.com/support/docview.wss?uid=swg21644047)
* [http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1862](http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1862)
* [https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c03922406-1%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken](https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c03922406-1%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken)
* [http://rhn.redhat.com/errata/RHSA-2013-1209.html](http://rhn.redhat.com/errata/RHSA-2013-1209.html)
* [http://rhn.redhat.com/errata/RHSA-2013-1207.html](http://rhn.redhat.com/errata/RHSA-2013-1207.html)
* [http://rhn.redhat.com/errata/RHSA-2013-1208.html](http://rhn.redhat.com/errata/RHSA-2013-1208.html)
* [http://secunia.com/advisories/55032](http://secunia.com/advisories/55032)
* [http://www.securityfocus.com/bid/64758](http://www.securityfocus.com/bid/64758)
* [http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html](http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2013:174](http://www.mandriva.com/security/advisories?name=MDVSA-2013:174)
* [http://support.apple.com/kb/HT6150](http://support.apple.com/kb/HT6150)
* [http://www.fujitsu.com/global/support/software/security/products-f/interstage-201303e.html](http://www.fujitsu.com/global/support/software/security/products-f/interstage-201303e.html)
* [http://www.securityfocus.com/bid/59826](http://www.securityfocus.com/bid/59826)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19534](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19534)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18790](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18790)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2013-1896 Signalée 10/07/2013mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
* [http://www.apache.org/dist/httpd/Announcement2.2.html](http://www.apache.org/dist/httpd/Announcement2.2.html)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/mod_dav.c?view=log](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/mod_dav.c?view=log)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/mod_dav.c?r1=1482522&r2=1485668&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/mod_dav.c?r1=1482522&r2=1485668&diff_format=h)
* [http://lists.opensuse.org/opensuse-updates/2013-08/msg00026.html](http://lists.opensuse.org/opensuse-updates/2013-08/msg00026.html)
* [http://rhn.redhat.com/errata/RHSA-2013-1156.html](http://rhn.redhat.com/errata/RHSA-2013-1156.html)
* [http://www.ubuntu.com/usn/USN-1903-1](http://www.ubuntu.com/usn/USN-1903-1)
* [http://lists.opensuse.org/opensuse-updates/2013-08/msg00029.html](http://lists.opensuse.org/opensuse-updates/2013-08/msg00029.html)
* [http://lists.opensuse.org/opensuse-updates/2013-08/msg00030.html](http://lists.opensuse.org/opensuse-updates/2013-08/msg00030.html)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21644047](http://www-01.ibm.com/support/docview.wss?uid=swg21644047)
* [http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1896](http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-1896)
* [https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c03922406-1%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken](https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c03922406-1%257CdocLocale%253D%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken)
* [http://rhn.redhat.com/errata/RHSA-2013-1209.html](http://rhn.redhat.com/errata/RHSA-2013-1209.html)
* [http://rhn.redhat.com/errata/RHSA-2013-1207.html](http://rhn.redhat.com/errata/RHSA-2013-1207.html)
* [http://rhn.redhat.com/errata/RHSA-2013-1208.html](http://rhn.redhat.com/errata/RHSA-2013-1208.html)
* [http://secunia.com/advisories/55032](http://secunia.com/advisories/55032)
* [http://support.apple.com/kb/HT6150](http://support.apple.com/kb/HT6150)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.securityfocus.com/bid/61129](http://www.securityfocus.com/bid/61129)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19747](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19747)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18835](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18835)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r05b5357d1f6bd106f41541ee7d87aafe3f5ea4dc3e9bde5ce09baff8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9b4b963760a3cb5a4a70c902f325c6c0337fe51d5b8570416f8f8729%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2013-6438 Signalée 18/03/2014The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/util.c?r1=1528718&r2=1556428&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/util.c?r1=1528718&r2=1556428&diff_format=h)
* [http://www.apache.org/dist/httpd/CHANGES_2.4.9](http://www.apache.org/dist/httpd/CHANGES_2.4.9)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/util.c](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/dav/main/util.c)
* [http://www.ubuntu.com/usn/USN-2152-1](http://www.ubuntu.com/usn/USN-2152-1)
* [http://www.securityfocus.com/bid/66303](http://www.securityfocus.com/bid/66303)
* [http://secunia.com/advisories/59345](http://secunia.com/advisories/59345)
* [http://secunia.com/advisories/59315](http://secunia.com/advisories/59315)
* [http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html](http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html)
* [https://blogs.oracle.com/sunsecurity/entry/multiple_input_validation_vulnerabilities_in1](https://blogs.oracle.com/sunsecurity/entry/multiple_input_validation_vulnerabilities_in1)
* [http://secunia.com/advisories/58230](http://secunia.com/advisories/58230)
* [http://secunia.com/advisories/60536](http://secunia.com/advisories/60536)
* [http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html](http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html)
* [https://support.apple.com/kb/HT6535](https://support.apple.com/kb/HT6535)
* [http://marc.info/?l=bugtraq&m=141390017113542&w=2](http://marc.info/?l=bugtraq&m=141390017113542&w=2)
* [http://www.vmware.com/security/advisories/VMSA-2014-0012.html](http://www.vmware.com/security/advisories/VMSA-2014-0012.html)
* [http://seclists.org/fulldisclosure/2014/Dec/23](http://seclists.org/fulldisclosure/2014/Dec/23)
* [http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html](http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html)
* [http://advisories.mageia.org/MGASA-2014-0135.html](http://advisories.mageia.org/MGASA-2014-0135.html)
* [http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html](http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html)
* [https://support.apple.com/HT204659](https://support.apple.com/HT204659)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21676091](http://www-01.ibm.com/support/docview.wss?uid=swg21676091)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21669554](http://www-01.ibm.com/support/docview.wss?uid=swg21669554)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21676092](http://www-01.ibm.com/support/docview.wss?uid=swg21676092)
* [http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698](http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698)
* [http://marc.info/?l=bugtraq&m=141017844705317&w=2](http://marc.info/?l=bugtraq&m=141017844705317&w=2)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES](http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES)
* [http://security.gentoo.org/glsa/glsa-201408-12.xml](http://security.gentoo.org/glsa/glsa-201408-12.xml)
* [https://puppet.com/security/cve/cve-2013-6438](https://puppet.com/security/cve/cve-2013-6438)
* [http://www.securityfocus.com/archive/1/534161/100/0/threaded](http://www.securityfocus.com/archive/1/534161/100/0/threaded)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2014-0098 Signalée 18/03/2014The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c?r1=1575394&r2=1575400&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c?r1=1575394&r2=1575400&diff_format=h)
* [http://www.apache.org/dist/httpd/CHANGES_2.4.9](http://www.apache.org/dist/httpd/CHANGES_2.4.9)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/loggers/mod_log_config.c)
* [http://www.ubuntu.com/usn/USN-2152-1](http://www.ubuntu.com/usn/USN-2152-1)
* [http://secunia.com/advisories/58915](http://secunia.com/advisories/58915)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21668973](http://www-01.ibm.com/support/docview.wss?uid=swg21668973)
* [http://www.securityfocus.com/bid/66303](http://www.securityfocus.com/bid/66303)
* [http://secunia.com/advisories/59345](http://secunia.com/advisories/59345)
* [http://secunia.com/advisories/59315](http://secunia.com/advisories/59315)
* [https://blogs.oracle.com/sunsecurity/entry/multiple_input_validation_vulnerabilities_in1](https://blogs.oracle.com/sunsecurity/entry/multiple_input_validation_vulnerabilities_in1)
* [http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html](http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html)
* [http://secunia.com/advisories/58230](http://secunia.com/advisories/58230)
* [http://secunia.com/advisories/60536](http://secunia.com/advisories/60536)
* [http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html](http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html)
* [https://support.apple.com/kb/HT6535](https://support.apple.com/kb/HT6535)
* [http://marc.info/?l=bugtraq&m=141390017113542&w=2](http://marc.info/?l=bugtraq&m=141390017113542&w=2)
* [http://www.vmware.com/security/advisories/VMSA-2014-0012.html](http://www.vmware.com/security/advisories/VMSA-2014-0012.html)
* [http://seclists.org/fulldisclosure/2014/Dec/23](http://seclists.org/fulldisclosure/2014/Dec/23)
* [http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html](http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html)
* [http://advisories.mageia.org/MGASA-2014-0135.html](http://advisories.mageia.org/MGASA-2014-0135.html)
* [http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html](http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html)
* [https://support.apple.com/HT204659](https://support.apple.com/HT204659)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21676091](http://www-01.ibm.com/support/docview.wss?uid=swg21676091)
* [http://www-01.ibm.com/support/docview.wss?uid=swg21676092](http://www-01.ibm.com/support/docview.wss?uid=swg21676092)
* [http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698](http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10698)
* [http://marc.info/?l=bugtraq&m=141017844705317&w=2](http://marc.info/?l=bugtraq&m=141017844705317&w=2)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES](http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES)
* [http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15320.html](http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15320.html)
* [http://security.gentoo.org/glsa/glsa-201408-12.xml](http://security.gentoo.org/glsa/glsa-201408-12.xml)
* [http://secunia.com/advisories/59219](http://secunia.com/advisories/59219)
* [https://puppet.com/security/cve/cve-2014-0098](https://puppet.com/security/cve/cve-2014-0098)
* [http://www.securityfocus.com/archive/1/534161/100/0/threaded](http://www.securityfocus.com/archive/1/534161/100/0/threaded)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2014-0118 Signalée 20/07/2014The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size.
* [https://bugzilla.redhat.com/show_bug.cgi?id=1120601](https://bugzilla.redhat.com/show_bug.cgi?id=1120601)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/filters/mod_deflate.c](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/filters/mod_deflate.c)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/filters/mod_deflate.c?r1=1604353&r2=1610501&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/filters/mod_deflate.c?r1=1604353&r2=1610501&diff_format=h)
* [http://httpd.apache.org/security/vulnerabilities_24.html](http://httpd.apache.org/security/vulnerabilities_24.html)
* [http://rhn.redhat.com/errata/RHSA-2014-1019.html](http://rhn.redhat.com/errata/RHSA-2014-1019.html)
* [http://rhn.redhat.com/errata/RHSA-2014-1021.html](http://rhn.redhat.com/errata/RHSA-2014-1021.html)
* [http://rhn.redhat.com/errata/RHSA-2014-1020.html](http://rhn.redhat.com/errata/RHSA-2014-1020.html)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2014:142](http://www.mandriva.com/security/advisories?name=MDVSA-2014:142)
* [http://www.securityfocus.com/bid/68745](http://www.securityfocus.com/bid/68745)
* [http://advisories.mageia.org/MGASA-2014-0304.html](http://advisories.mageia.org/MGASA-2014-0304.html)
* [http://www.debian.org/security/2014/dsa-2989](http://www.debian.org/security/2014/dsa-2989)
* [http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html](http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html)
* [http://advisories.mageia.org/MGASA-2014-0305.html](http://advisories.mageia.org/MGASA-2014-0305.html)
* [http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html](http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html)
* [https://support.apple.com/HT204659](https://support.apple.com/HT204659)
* [http://marc.info/?l=bugtraq&m=144493176821532&w=2](http://marc.info/?l=bugtraq&m=144493176821532&w=2)
* [http://marc.info/?l=bugtraq&m=143403519711434&w=2](http://marc.info/?l=bugtraq&m=143403519711434&w=2)
* [http://marc.info/?l=bugtraq&m=143748090628601&w=2](http://marc.info/?l=bugtraq&m=143748090628601&w=2)
* [http://marc.info/?l=bugtraq&m=144050155601375&w=2](http://marc.info/?l=bugtraq&m=144050155601375&w=2)
* [https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246](https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246)
* [https://security.gentoo.org/glsa/201504-03](https://security.gentoo.org/glsa/201504-03)
* [http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES](http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES)
* [https://puppet.com/security/cve/cve-2014-0118](https://puppet.com/security/cve/cve-2014-0118)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2014-0226 Signalée 20/07/2014Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the status_handler function in modules/generators/mod_status.c and the lua_ap_scoreboard_worker function in modules/lua/lua_request.c.
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_status.c](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_status.c)
* [http://httpd.apache.org/security/vulnerabilities_24.html](http://httpd.apache.org/security/vulnerabilities_24.html)
* [http://zerodayinitiative.com/advisories/ZDI-14-236/](http://zerodayinitiative.com/advisories/ZDI-14-236/)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/lua/lua_request.c?r1=1588989&r2=1610491&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/lua/lua_request.c?r1=1588989&r2=1610491&diff_format=h)
* [https://bugzilla.redhat.com/show_bug.cgi?id=1120603](https://bugzilla.redhat.com/show_bug.cgi?id=1120603)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_status.c?r1=1450998&r2=1610491&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_status.c?r1=1450998&r2=1610491&diff_format=h)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/lua/lua_request.c](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/lua/lua_request.c)
* [http://rhn.redhat.com/errata/RHSA-2014-1019.html](http://rhn.redhat.com/errata/RHSA-2014-1019.html)
* [http://rhn.redhat.com/errata/RHSA-2014-1021.html](http://rhn.redhat.com/errata/RHSA-2014-1021.html)
* [http://rhn.redhat.com/errata/RHSA-2014-1020.html](http://rhn.redhat.com/errata/RHSA-2014-1020.html)
* [http://seclists.org/fulldisclosure/2014/Jul/114](http://seclists.org/fulldisclosure/2014/Jul/114)
* [http://secunia.com/advisories/60536](http://secunia.com/advisories/60536)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2014:142](http://www.mandriva.com/security/advisories?name=MDVSA-2014:142)
* [http://www.exploit-db.com/exploits/34133](http://www.exploit-db.com/exploits/34133)
* [http://www.securityfocus.com/bid/68678](http://www.securityfocus.com/bid/68678)
* [http://www.osvdb.org/109216](http://www.osvdb.org/109216)
* [http://advisories.mageia.org/MGASA-2014-0304.html](http://advisories.mageia.org/MGASA-2014-0304.html)
* [http://www.debian.org/security/2014/dsa-2989](http://www.debian.org/security/2014/dsa-2989)
* [http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html](http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html)
* [http://advisories.mageia.org/MGASA-2014-0305.html](http://advisories.mageia.org/MGASA-2014-0305.html)
* [http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html](http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html)
* [https://support.apple.com/HT204659](https://support.apple.com/HT204659)
* [http://marc.info/?l=bugtraq&m=144493176821532&w=2](http://marc.info/?l=bugtraq&m=144493176821532&w=2)
* [http://marc.info/?l=bugtraq&m=143748090628601&w=2](http://marc.info/?l=bugtraq&m=143748090628601&w=2)
* [http://marc.info/?l=bugtraq&m=144050155601375&w=2](http://marc.info/?l=bugtraq&m=144050155601375&w=2)
* [http://marc.info/?l=bugtraq&m=143403519711434&w=2](http://marc.info/?l=bugtraq&m=143403519711434&w=2)
* [https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246](https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246)
* [https://security.gentoo.org/glsa/201504-03](https://security.gentoo.org/glsa/201504-03)
* [http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES](http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES)
* [http://security.gentoo.org/glsa/glsa-201408-12.xml](http://security.gentoo.org/glsa/glsa-201408-12.xml)
* [https://puppet.com/security/cve/cve-2014-0226](https://puppet.com/security/cve/cve-2014-0226)
* [https://www.povonsec.com/apache-2-4-7-exploit/](https://www.povonsec.com/apache-2-4-7-exploit/)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2014-0231 Signalée 20/07/2014The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.
* [https://bugzilla.redhat.com/show_bug.cgi?id=1120596](https://bugzilla.redhat.com/show_bug.cgi?id=1120596)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_cgid.c?r1=1482522&r2=1535125&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_cgid.c?r1=1482522&r2=1535125&diff_format=h)
* [http://httpd.apache.org/security/vulnerabilities_24.html](http://httpd.apache.org/security/vulnerabilities_24.html)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_cgid.c](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_cgid.c)
* [http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_cgid.c?r1=1565711&r2=1610509&diff_format=h](http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/generators/mod_cgid.c?r1=1565711&r2=1610509&diff_format=h)
* [http://rhn.redhat.com/errata/RHSA-2014-1019.html](http://rhn.redhat.com/errata/RHSA-2014-1019.html)
* [http://rhn.redhat.com/errata/RHSA-2014-1021.html](http://rhn.redhat.com/errata/RHSA-2014-1021.html)
* [http://rhn.redhat.com/errata/RHSA-2014-1020.html](http://rhn.redhat.com/errata/RHSA-2014-1020.html)
* [http://secunia.com/advisories/60536](http://secunia.com/advisories/60536)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2014:142](http://www.mandriva.com/security/advisories?name=MDVSA-2014:142)
* [http://advisories.mageia.org/MGASA-2014-0304.html](http://advisories.mageia.org/MGASA-2014-0304.html)
* [http://www.securityfocus.com/bid/68742](http://www.securityfocus.com/bid/68742)
* [http://www.debian.org/security/2014/dsa-2989](http://www.debian.org/security/2014/dsa-2989)
* [http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html](http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html)
* [http://packetstormsecurity.com/files/130769/RSA-Digital-Certificate-Solution-XSS-Denial-Of-Service.html](http://packetstormsecurity.com/files/130769/RSA-Digital-Certificate-Solution-XSS-Denial-Of-Service.html)
* [http://advisories.mageia.org/MGASA-2014-0305.html](http://advisories.mageia.org/MGASA-2014-0305.html)
* [http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html](http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.html)
* [https://support.apple.com/HT204659](https://support.apple.com/HT204659)
* [http://marc.info/?l=bugtraq&m=144493176821532&w=2](http://marc.info/?l=bugtraq&m=144493176821532&w=2)
* [http://marc.info/?l=bugtraq&m=143403519711434&w=2](http://marc.info/?l=bugtraq&m=143403519711434&w=2)
* [http://marc.info/?l=bugtraq&m=143748090628601&w=2](http://marc.info/?l=bugtraq&m=143748090628601&w=2)
* [http://marc.info/?l=bugtraq&m=144050155601375&w=2](http://marc.info/?l=bugtraq&m=144050155601375&w=2)
* [https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246](https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246)
* [https://security.gentoo.org/glsa/201504-03](https://security.gentoo.org/glsa/201504-03)
* [http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES](http://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x/CHANGES)
* [https://puppet.com/security/cve/cve-2014-0231](https://puppet.com/security/cve/cve-2014-0231)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9821b0a32a1d0a1b4947abb6f3630053fcbb2ec905d9a32c2bd4d4ee%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2015-0228 Signalée 08/03/2015The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
* [https://github.com/apache/httpd/commit/643f0fcf3b8ab09a68f0ecd2aa37aafeda3e63ef](https://github.com/apache/httpd/commit/643f0fcf3b8ab09a68f0ecd2aa37aafeda3e63ef)
* [http://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x/CHANGES](http://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x/CHANGES)
* [http://www.ubuntu.com/usn/USN-2523-1](http://www.ubuntu.com/usn/USN-2523-1)
* [http://lists.opensuse.org/opensuse-updates/2015-03/msg00006.html](http://lists.opensuse.org/opensuse-updates/2015-03/msg00006.html)
* [http://advisories.mageia.org/MGASA-2015-0099.html](http://advisories.mageia.org/MGASA-2015-0099.html)
* [http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html](http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html)
* [https://support.apple.com/kb/HT205031](https://support.apple.com/kb/HT205031)
* [http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html](http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html)
* [https://support.apple.com/HT205219](https://support.apple.com/HT205219)
* [http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html](http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html)
* [http://www.securityfocus.com/bid/91787](http://www.securityfocus.com/bid/91787)
* [http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html](http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html)
* [http://www.securityfocus.com/bid/73041](http://www.securityfocus.com/bid/73041)
* [http://www.securitytracker.com/id/1032967](http://www.securitytracker.com/id/1032967)
* [http://rhn.redhat.com/errata/RHSA-2015-1666.html](http://rhn.redhat.com/errata/RHSA-2015-1666.html)
* [https://github.com/apache/httpd/commit/78eb3b9235515652ed141353d98c239237030410](https://github.com/apache/httpd/commit/78eb3b9235515652ed141353d98c239237030410)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2015-3183 Signalée 20/07/2015The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.
* [http://httpd.apache.org/security/vulnerabilities_24.html](http://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.apache.org/dist/httpd/CHANGES_2.4](http://www.apache.org/dist/httpd/CHANGES_2.4)
* [https://github.com/apache/httpd/commit/e427c41257957b57036d5a549b260b6185d1dd73](https://github.com/apache/httpd/commit/e427c41257957b57036d5a549b260b6185d1dd73)
* [http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html](http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html)
* [https://support.apple.com/kb/HT205031](https://support.apple.com/kb/HT205031)
* [http://www.ubuntu.com/usn/USN-2686-1](http://www.ubuntu.com/usn/USN-2686-1)
* [http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html](http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html)
* [https://support.apple.com/HT205219](https://support.apple.com/HT205219)
* [http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html](http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html)
* [http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html](http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html)
* [http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html](http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html)
* [http://www.securityfocus.com/bid/91787](http://www.securityfocus.com/bid/91787)
* [http://marc.info/?l=bugtraq&m=144493176821532&w=2](http://marc.info/?l=bugtraq&m=144493176821532&w=2)
* [http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html](http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html)
* [http://www.securityfocus.com/bid/75963](http://www.securityfocus.com/bid/75963)
* [http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735](http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10735)
* [http://rhn.redhat.com/errata/RHSA-2016-0062.html](http://rhn.redhat.com/errata/RHSA-2016-0062.html)
* [http://rhn.redhat.com/errata/RHSA-2016-0061.html](http://rhn.redhat.com/errata/RHSA-2016-0061.html)
* [https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04926789](https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04926789)
* [https://access.redhat.com/errata/RHSA-2015:2660](https://access.redhat.com/errata/RHSA-2015:2660)
* [http://rhn.redhat.com/errata/RHSA-2015-2661.html](http://rhn.redhat.com/errata/RHSA-2015-2661.html)
* [https://access.redhat.com/errata/RHSA-2015:2659](https://access.redhat.com/errata/RHSA-2015:2659)
* [https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246](https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04832246)
* [http://lists.opensuse.org/opensuse-updates/2015-10/msg00011.html](http://lists.opensuse.org/opensuse-updates/2015-10/msg00011.html)
* [http://www.debian.org/security/2015/dsa-3325](http://www.debian.org/security/2015/dsa-3325)
* [http://rhn.redhat.com/errata/RHSA-2015-1668.html](http://rhn.redhat.com/errata/RHSA-2015-1668.html)
* [http://rhn.redhat.com/errata/RHSA-2015-1667.html](http://rhn.redhat.com/errata/RHSA-2015-1667.html)
* [https://security.gentoo.org/glsa/201610-02](https://security.gentoo.org/glsa/201610-02)
* [http://www.securitytracker.com/id/1032967](http://www.securitytracker.com/id/1032967)
* [https://puppet.com/security/cve/CVE-2015-3183](https://puppet.com/security/cve/CVE-2015-3183)
* [http://rhn.redhat.com/errata/RHSA-2016-2056.html](http://rhn.redhat.com/errata/RHSA-2016-2056.html)
* [http://rhn.redhat.com/errata/RHSA-2016-2055.html](http://rhn.redhat.com/errata/RHSA-2016-2055.html)
* [http://rhn.redhat.com/errata/RHSA-2016-2054.html](http://rhn.redhat.com/errata/RHSA-2016-2054.html)
* [http://rhn.redhat.com/errata/RHSA-2015-1666.html](http://rhn.redhat.com/errata/RHSA-2015-1666.html)
* [https://github.com/apache/httpd/commit/a6027e56924bb6227c1fdbf6f91e7e2438338be6](https://github.com/apache/httpd/commit/a6027e56924bb6227c1fdbf6f91e7e2438338be6)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/ra7f6aeb28661fbf826969526585f16856abc4615877875f9d3b35ef4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r83109088737656fa6307bd99ab40f8ff0269ae58d3f7272d7048494a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df39b094be286b9e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb14daf9cc4e28d18cdc15d6a6ca74e565672fabf7ad89541071d008b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2016-8612 Signalée 09/03/2018Apache HTTP Server mod_cluster before version httpd 2.4.23 is vulnerable to an Improper Input Validation in the protocol parsing logic in the load balancer resulting in a Segmentation Fault in the serving httpd process.
* [https://bugzilla.redhat.com/show_bug.cgi?id=1387605](https://bugzilla.redhat.com/show_bug.cgi?id=1387605)
* [https://access.redhat.com/errata/RHSA-2017:0194](https://access.redhat.com/errata/RHSA-2017:0194)
* [https://access.redhat.com/errata/RHSA-2017:0193](https://access.redhat.com/errata/RHSA-2017:0193)
* [http://www.securityfocus.com/bid/94939](http://www.securityfocus.com/bid/94939)
* [http://rhn.redhat.com/errata/RHSA-2016-2957.html](http://rhn.redhat.com/errata/RHSA-2016-2957.html)
* [https://security.netapp.com/advisory/ntap-20180601-0005/](https://security.netapp.com/advisory/ntap-20180601-0005/) -
Moyenne CVE-2018-1301 Signalée 26/03/2018A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.openwall.com/lists/oss-security/2018/03/24/2](http://www.openwall.com/lists/oss-security/2018/03/24/2)
* [http://www.securitytracker.com/id/1040573](http://www.securitytracker.com/id/1040573)
* [http://www.securityfocus.com/bid/103515](http://www.securityfocus.com/bid/103515)
* [https://www.debian.org/security/2018/dsa-4164](https://www.debian.org/security/2018/dsa-4164)
* [https://usn.ubuntu.com/3627-1/](https://usn.ubuntu.com/3627-1/)
* [https://usn.ubuntu.com/3627-2/](https://usn.ubuntu.com/3627-2/)
* [https://lists.debian.org/debian-lts-announce/2018/05/msg00020.html](https://lists.debian.org/debian-lts-announce/2018/05/msg00020.html)
* [https://security.netapp.com/advisory/ntap-20180601-0004/](https://security.netapp.com/advisory/ntap-20180601-0004/)
* [https://access.redhat.com/errata/RHSA-2018:3558](https://access.redhat.com/errata/RHSA-2018:3558)
* [https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us)
* [https://access.redhat.com/errata/RHSA-2019:0367](https://access.redhat.com/errata/RHSA-2019:0367)
* [https://access.redhat.com/errata/RHSA-2019:0366](https://access.redhat.com/errata/RHSA-2019:0366)
* [https://usn.ubuntu.com/3937-2/](https://usn.ubuntu.com/3937-2/)
* [https://www.tenable.com/security/tns-2019-09](https://www.tenable.com/security/tns-2019-09)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d978497a1f794af53be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2018-1302 Signalée 26/03/2018When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [http://www.openwall.com/lists/oss-security/2018/03/24/5](http://www.openwall.com/lists/oss-security/2018/03/24/5)
* [http://www.securitytracker.com/id/1040567](http://www.securitytracker.com/id/1040567)
* [http://www.securityfocus.com/bid/103528](http://www.securityfocus.com/bid/103528)
* [https://security.netapp.com/advisory/ntap-20180601-0004/](https://security.netapp.com/advisory/ntap-20180601-0004/)
* [https://usn.ubuntu.com/3783-1/](https://usn.ubuntu.com/3783-1/)
* [https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us](https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us)
* [https://access.redhat.com/errata/RHSA-2019:0367](https://access.redhat.com/errata/RHSA-2019:0367)
* [https://access.redhat.com/errata/RHSA-2019:0366](https://access.redhat.com/errata/RHSA-2019:0366)
* [https://www.tenable.com/security/tns-2019-09](https://www.tenable.com/security/tns-2019-09)
* [https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfcf929bd33a6833e3f0c35eebdad70d5060665f9c4e17ea467c66770%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da80414485b3abcc9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E) -
Moyenne CVE-2022-28330 Signalée 09/06/2022Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
* [http://www.openwall.com/lists/oss-security/2022/06/08/3](http://www.openwall.com/lists/oss-security/2022/06/08/3)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://security.netapp.com/advisory/ntap-20220624-0005/](https://security.netapp.com/advisory/ntap-20220624-0005/) -
Moyenne CVE-2022-28614 Signalée 09/06/2022The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'ap_rputs' function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue.
* [http://www.openwall.com/lists/oss-security/2022/06/08/4](http://www.openwall.com/lists/oss-security/2022/06/08/4)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://security.netapp.com/advisory/ntap-20220624-0005/](https://security.netapp.com/advisory/ntap-20220624-0005/)
* [https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND/)
* [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ/) -
Moyenne CVE-2022-37436 Signalée 17/01/2023Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://security.gentoo.org/glsa/202309-01](https://security.gentoo.org/glsa/202309-01) -
Moyenne CVE-2026-29170 Signalée 08/06/2026A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
* [http://www.openwall.com/lists/oss-security/2026/06/08/5](http://www.openwall.com/lists/oss-security/2026/06/08/5)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Moyenne CVE-2026-33006 Signalée 04/05/2026A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
* [http://www.openwall.com/lists/oss-security/2026/05/04/21](http://www.openwall.com/lists/oss-security/2026/05/04/21)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Moyenne CVE-2026-33857 Signalée 04/05/2026Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
* [http://www.openwall.com/lists/oss-security/2026/05/04/15](http://www.openwall.com/lists/oss-security/2026/05/04/15)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Moyenne CVE-2026-34032 Signalée 04/05/2026Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
* [http://www.openwall.com/lists/oss-security/2026/05/04/16](http://www.openwall.com/lists/oss-security/2026/05/04/16)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) -
Basse CVE-2007-6421 Signalée 08/01/2008Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
* [http://httpd.apache.org/security/vulnerabilities_22.html](http://httpd.apache.org/security/vulnerabilities_22.html)
* [http://www.redhat.com/support/errata/RHSA-2008-0008.html](http://www.redhat.com/support/errata/RHSA-2008-0008.html)
* [http://www.securityfocus.com/bid/27236](http://www.securityfocus.com/bid/27236)
* [http://www.mandriva.com/security/advisories?name=MDVSA-2008:016](http://www.mandriva.com/security/advisories?name=MDVSA-2008:016)
* [http://secunia.com/advisories/28526](http://secunia.com/advisories/28526)
* [http://www.ubuntu.com/usn/usn-575-1](http://www.ubuntu.com/usn/usn-575-1)
* [http://secunia.com/advisories/28749](http://secunia.com/advisories/28749)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html)
* [https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html](https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html)
* [http://secunia.com/advisories/28977](http://secunia.com/advisories/28977)
* [http://docs.info.apple.com/article.html?artnum=307562](http://docs.info.apple.com/article.html?artnum=307562)
* [http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html](http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html)
* [http://secunia.com/advisories/29420](http://secunia.com/advisories/29420)
* [http://securityreason.com/securityalert/3523](http://securityreason.com/securityalert/3523)
* [http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html](http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html)
* [http://secunia.com/advisories/29640](http://secunia.com/advisories/29640)
* [http://www.redhat.com/support/errata/RHSA-2008-0009.html](http://www.redhat.com/support/errata/RHSA-2008-0009.html)
* [http://www.vupen.com/english/advisories/2008/0048](http://www.vupen.com/english/advisories/2008/0048)
* [http://www.vupen.com/english/advisories/2008/0924/references](http://www.vupen.com/english/advisories/2008/0924/references)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/39474](https://exchange.xforce.ibmcloud.com/vulnerabilities/39474)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8651](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8651)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10664](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10664)
* [http://www.securityfocus.com/archive/1/486169/100/0/threaded](http://www.securityfocus.com/archive/1/486169/100/0/threaded)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Basse CVE-2008-0456 Signalée 25/01/2008CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.
* [http://www.mindedsecurity.com/MSA01150108.html](http://www.mindedsecurity.com/MSA01150108.html)
* [http://www.securityfocus.com/bid/27409](http://www.securityfocus.com/bid/27409)
* [http://securitytracker.com/id?1019256](http://securitytracker.com/id?1019256)
* [http://security.gentoo.org/glsa/glsa-200803-19.xml](http://security.gentoo.org/glsa/glsa-200803-19.xml)
* [http://secunia.com/advisories/29348](http://secunia.com/advisories/29348)
* [http://securityreason.com/securityalert/3575](http://securityreason.com/securityalert/3575)
* [http://www.vupen.com/english/advisories/2009/1297](http://www.vupen.com/english/advisories/2009/1297)
* [http://secunia.com/advisories/35074](http://secunia.com/advisories/35074)
* [http://lists.apple.com/archives/security-announce/2009/May/msg00002.html](http://lists.apple.com/archives/security-announce/2009/May/msg00002.html)
* [http://support.apple.com/kb/HT3549](http://support.apple.com/kb/HT3549)
* [http://www.us-cert.gov/cas/techalerts/TA09-133A.html](http://www.us-cert.gov/cas/techalerts/TA09-133A.html)
* [http://rhn.redhat.com/errata/RHSA-2013-0130.html](http://rhn.redhat.com/errata/RHSA-2013-0130.html)
* [https://exchange.xforce.ibmcloud.com/vulnerabilities/39893](https://exchange.xforce.ibmcloud.com/vulnerabilities/39893)
* [http://www.securityfocus.com/archive/1/486847/100/0/threaded](http://www.securityfocus.com/archive/1/486847/100/0/threaded)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Basse CVE-2009-3094 Signalée 08/09/2009The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
* [http://intevydis.com/vd-list.shtml](http://intevydis.com/vd-list.shtml)
* [http://www.intevydis.com/blog/?p=59](http://www.intevydis.com/blog/?p=59)
* [http://secunia.com/advisories/36549](http://secunia.com/advisories/36549)
* [http://secunia.com/advisories/37152](http://secunia.com/advisories/37152)
* [http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html](http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00006.html)
* [http://www.debian.org/security/2009/dsa-1934](http://www.debian.org/security/2009/dsa-1934)
* [http://wiki.rpath.com/Advisories:rPSA-2009-0155](http://wiki.rpath.com/Advisories:rPSA-2009-0155)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html)
* [https://bugzilla.redhat.com/show_bug.cgi?id=521619](https://bugzilla.redhat.com/show_bug.cgi?id=521619)
* [https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html](https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PK96858](http://www-01.ibm.com/support/docview.wss?uid=swg1PK96858)
* [http://www.vupen.com/english/advisories/2010/0609](http://www.vupen.com/english/advisories/2010/0609)
* [http://www-01.ibm.com/support/docview.wss?uid=swg1PM09161](http://www-01.ibm.com/support/docview.wss?uid=swg1PM09161)
* [http://marc.info/?l=bugtraq&m=126998684522511&w=2](http://marc.info/?l=bugtraq&m=126998684522511&w=2)
* [http://marc.info/?l=bugtraq&m=133355494609819&w=2](http://marc.info/?l=bugtraq&m=133355494609819&w=2)
* [http://marc.info/?l=bugtraq&m=127557640302499&w=2](http://marc.info/?l=bugtraq&m=127557640302499&w=2)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8087](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8087)
* [https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10981](https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10981)
* [http://www.securityfocus.com/archive/1/508075/100/0/threaded](http://www.securityfocus.com/archive/1/508075/100/0/threaded)
* [https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E)
* [https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E) -
Non classée CVE-2023-38709 Signalée 04/04/2024Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
* [http://seclists.org/fulldisclosure/2024/Jul/18](http://seclists.org/fulldisclosure/2024/Jul/18)
* [http://seclists.org/fulldisclosure/2024/Jul/18](http://seclists.org/fulldisclosure/2024/Jul/18)
* [http://www.openwall.com/lists/oss-security/2024/04/04/3](http://www.openwall.com/lists/oss-security/2024/04/04/3)
* [http://www.openwall.com/lists/oss-security/2024/04/04/3](http://www.openwall.com/lists/oss-security/2024/04/04/3)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
* [https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html](https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html)
* [https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html](https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/)
* [https://security.netapp.com/advisory/ntap-20240415-0013/](https://security.netapp.com/advisory/ntap-20240415-0013/)
* [https://security.netapp.com/advisory/ntap-20240415-0013/](https://security.netapp.com/advisory/ntap-20240415-0013/)
* [https://support.apple.com/kb/HT214119](https://support.apple.com/kb/HT214119)
* [https://support.apple.com/kb/HT214119](https://support.apple.com/kb/HT214119) -
Non classée CVE-2025-49812 Signalée 10/07/2025In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.
* [https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html)
Paquets abandonnés
à remplacer ou à surveiller
-
1 oct. 2026, 16:08+90 nouvelles185 au total
-
24 sept. 2026, 03:02−91 fermées95 au total
-
2 sept. 2026, 03:02+1 nouvelles186 au total
-
8 août 2026, 03:02+2 nouvelles185 au total
-
4 août 2026, 03:02+2 nouvelles183 au total
-
24 juil. 2026, 03:03+3 nouvelles181 au total
-
22 juil. 2026, 03:03+1 nouvelles178 au total
-
21 juil. 2026, 03:03+5 nouvelles177 au total
-
11 juil. 2026, 03:01+2 nouvelles172 au total
-
7 juil. 2026, 03:01+91 nouvelles170 au total
-
2 juil. 2026, 03:04+1 nouvelles79 au total
-
1 juil. 2026, 03:04−91 fermées78 au total
-
20 juin 2026, 03:01+3 nouvelles169 au total
-
13 juin 2026, 03:02+2 nouvelles166 au total
-
11 juin 2026, 03:02+2 nouvelles164 au total
-
9 juin 2026, 03:02+1 nouvelles162 au total
-
28 mai 2026, 03:02+7 nouvelles161 au total
-
27 mai 2026, 03:02+1 nouvelles154 au total
-
21 mai 2026, 03:02+18 nouvelles153 au total
-
8 mai 2026, 03:02+1 nouvelles135 au total
-
6 mai 2026, 03:02+6 nouvelles134 au total
-
1 mai 2026, 03:02+46 nouvelles +3 abandonnés128 au total
-
30 avr. 2026, 03:02−43 fermées −3 abandonnés82 au total
-
29 avr. 2026, 03:02+2 nouvelles125 au total
-
29 janv. 2026, 02:03+1 nouvelles123 au total
-
10 déc. 2025, 02:03+82 nouvelles122 au total
-
9 déc. 2025, 02:03−81 fermées40 au total
-
13 nov. 2025, 02:03+1 nouvelles121 au total
-
26 août 2025, 03:02+1 nouvelles120 au total
-
7 août 2025, 03:03+81 nouvelles119 au total
-
6 août 2025, 03:04−81 fermées38 au total
-
5 août 2025, 03:03+81 nouvelles119 au total
-
31 juil. 2025, 03:05−80 fermées38 au total
-
26 juil. 2025, 03:03+1 nouvelles118 au total
-
7 juil. 2025, 03:03+1 nouvelles117 au total
-
23 juin 2025, 16:25−64 fermées116 au total
-
19 juin 2025, 03:01+1 nouvelles180 au total
-
5 avr. 2025, 03:01+2 nouvelles179 au total
-
28 févr. 2025, 02:01+177 nouvelles +3 abandonnés177 au total
-
21 févr. 2025, 03:25−177 fermées −3 abandonnés0 au total
-
4 févr. 2025, 02:01+1 nouvelles177 au total
-
23 janv. 2025, 02:01+3 nouvelles176 au total
-
22 janv. 2025, 02:01+1 nouvelles173 au total
-
4 janv. 2025, 02:01+7 nouvelles172 au total
-
28 déc. 2024, 02:01+4 nouvelles165 au total
-
27 nov. 2024, 02:01+1 nouvelles161 au total
-
21 nov. 2024, 02:01+1 nouvelles160 au total
-
19 nov. 2024, 02:01+2 nouvelles159 au total
-
9 nov. 2024, 02:01+138 nouvelles157 au total
-
7 nov. 2024, 02:22+6 nouvelles19 au total
-
8 oct. 2024, 03:21+5 nouvelles13 au total
-
10 sept. 2024, 03:21+1 nouvelles8 au total
-
30 août 2024, 03:21+2 nouvelles7 au total
-
24 juil. 2024, 03:23−136 fermées5 au total
-
15 juil. 2024, 12:27+77 nouvelles141 au total
-
15 juil. 2024, 12:26−77 fermées64 au total
-
15 juil. 2024, 12:26+77 nouvelles141 au total
-
12 juil. 2024, 08:51+59 nouvelles64 au total
-
30 mai 2024, 03:00+1 nouvelles5 au total
Badges
[](https://audit.security.code-rhapsodie.fr/fr/project/018f7749-fa00-72c1-b40e-6a9a9b78b41b)
[](https://audit.security.code-rhapsodie.fr/fr/project/018f7749-fa00-72c1-b40e-6a9a9b78b41b)
[](https://audit.security.code-rhapsodie.fr/fr/project/018f7749-fa00-72c1-b40e-6a9a9b78b41b)
[](https://audit.security.code-rhapsodie.fr/fr/project/018f7749-fa00-72c1-b40e-6a9a9b78b41b)