Red Hat Customer Portal

Skip to main content

Main Navigation

  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Tower
      • Red Hat Ansible Engine
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat Cloud Infrastructure
      • Red Hat Cloud Suite
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat OpenShift Application Runtimes
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • JBoss Development and Management
      • Back
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat JBoss Data Grid
      • Red Hat JBoss Web Server
      • Red Hat JBoss Operations Network
      • Red Hat Developer Studio
    • JBoss Integration and Automation
      • Back
      • Red Hat JBoss Data Virtualization
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
      • Red Hat 3scale API Management
    • Mobile
      • Back
      • Red Hat Mobile Application Platform
    • Support
    • Production Support
    • Development Support
    • Product Life Cycle & Update Policies
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem
    • Browse Certified Solutions
    • Partner Resources
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • Español
    • Deutsch
    • Italiano
    • 한국어
    • Français
    • 日本語
    • Português
    • 中文 (中国)
    • русский
Red Hat Logo Customer Portal
  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Tower
      • Red Hat Ansible Engine
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat Cloud Infrastructure
      • Red Hat Cloud Suite
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat OpenShift Application Runtimes
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • JBoss Development and Management
      • Back
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat JBoss Data Grid
      • Red Hat JBoss Web Server
      • Red Hat JBoss Operations Network
      • Red Hat Developer Studio
    • JBoss Integration and Automation
      • Back
      • Red Hat JBoss Data Virtualization
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
      • Red Hat 3scale API Management
    • Mobile
      • Back
      • Red Hat Mobile Application Platform
    • Support
    • Production Support
    • Development Support
    • Product Life Cycle & Update Policies
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem
    • Browse Certified Solutions
    • Partner Resources
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • Español
    • Deutsch
    • Italiano
    • 한국어
    • Français
    • 日本語
    • Português
    • 中文 (中国)
    • русский
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Search
  • Log In
  • Language
Troubleshooting an issue? Try Solution Engine—our new support tool.

Log in to Your Red Hat Account

Log In

Your Red Hat account gives you access to your profile, preferences, and services, depending on your status.

Register

If you are a new customer, register now for access to product evaluations and purchasing capabilities.

Need access to an account?

If your company has an existing Red Hat account, your organization administrator can grant you access.

If you have any questions, please contact customer service.

Red Hat Account Number:

Red Hat Account

  • Account Details
  • User Management
  • Account Maintenance

Customer Portal

  • My Profile
  • Notifications
  • Help

For your security, if you’re on a public computer and have finished using your Red Hat services, please be sure to log out.

Log Out

Select Your Language

  • English
  • Español
  • Deutsch
  • Italiano
  • 한국어
  • Français
  • 日本語
  • Português
  • 中文 (中国)
  • русский
Red Hat Customer Portal
  • Products & Services
  • Tools
  • Security
  • Community
  • Infrastructure and Management

  • Cloud Computing

  • Storage

  • JBoss Development and Management

  • JBoss Integration and Automation

  • Mobile

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Tower
  • Red Hat Ansible Engine
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat Cloud Infrastructure
  • Red Hat Cloud Suite
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat OpenShift Application Runtimes
  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat Openshift Container Storage
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat JBoss Data Grid
  • Red Hat JBoss Web Server
  • Red Hat JBoss Operations Network
  • Red Hat Developer Studio
  • Red Hat JBoss Data Virtualization
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
  • Red Hat 3scale API Management
  • Red Hat Mobile Application Platform
View All Products
  • Support
  • Production Support
  • Development Support
  • Product Life Cycle & Update Policies

Services

  • Consulting
  • Technical Account Management
  • Training & Certifications
  • Documentation
  • Red Hat Enterprise Linux
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Ecosystem
  • Browse Certified Solutions
  • Partner Resources

Tools

  • Solution Engine
  • Packages
  • Errata
  • Customer Portal Labs
  • Configuration
  • Deployment
  • Security
  • Troubleshooting
  • Red Hat Insights

Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

Red Hat Product Security Center

Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

Product Security Center

Security Updates

  • Security Advisories
  • Red Hat CVE Database
  • Security Labs

Keep your systems secure with Red Hat's specialized responses for high-priority security vulnerabilities.

  • View Responses

Resources

  • Overview
  • Security Blog
  • Security Measurement
  • Severity Ratings
  • Backporting Policies
  • Product Signing (GPG) Keys

Customer Portal Community

  • Discussions
  • Blogs
  • Private Groups
  • Community Activity

Customer Events

  • Red Hat Convergence
  • Red Hat Summit

Stories

  • Red Hat Subscription Value
  • You Asked. We Acted.
  • Open Source Communities
Red Hat Product Errata RHSA-2007:0746 - Security Advisory
Issued:
2007-11-07
Updated:
2007-11-07

RHSA-2007:0746 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: httpd security, bug fix, and enhancement update

Type/Severity

Security Advisory: Moderate

Topic

Updated httpd packages that fix a security issue, fix various bugs, and
add enhancements, are now available for Red Hat Enterprise Linux 5.

This update has been rated as having moderate security impact by the Red
Hat Security Response Team.

Description

The Apache HTTP Server is a popular and freely-available Web server.

A flaw was found in the Apache HTTP Server mod_proxy module. On sites where
a reverse proxy is configured, a remote attacker could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. On sites where a forward proxy is configured, an attacker
could cause a similar crash if a user could be persuaded to visit a
malicious site using the proxy. This could lead to a denial of service if
using a threaded Multi-Processing Module. (CVE-2007-3847)

As well, these updated packages fix the following bugs:

  • Set-Cookie headers with a status code of 3xx are not forwarded to
    clients when the "ProxyErrorOverride" directive is enabled. These
    responses are overridden at the proxy. Only the responses with status
    codes of 4xx and 5xx are overridden in these updated packages.
  • the default "/etc/logrotate.d/httpd" script incorrectly invoked the kill
    command, instead of using the "/sbin/service httpd restart" command. If you
    configured the httpd PID to be in a location other than
    "/var/run/httpd.pid", the httpd logs failed to be rotated. This has been
    resolved in these updated packages.
  • the "ProxyTimeout" directive was not inherited across virtual host
    definitions.
  • the logresolve utility was unable to read lines longer the 1024 bytes.

This update adds the following enhancements:

  • a new configuration option has been added, "ServerTokens Full-Release",
    which adds the package release to the server version string, which is
    returned in the "Server" response header.
  • a new module has been added, mod_version, which allows configuration
    files to be written containing sections, which are evaluated only if the
    version of httpd used matches a specified condition.

Users of httpd are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements.

Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network. Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/FAQ_58_10188

Affected Products

  • Red Hat Enterprise Linux Server 5 x86_64
  • Red Hat Enterprise Linux Server 5 ia64
  • Red Hat Enterprise Linux Server 5 i386
  • Red Hat Enterprise Linux Workstation 5 x86_64
  • Red Hat Enterprise Linux Workstation 5 i386
  • Red Hat Enterprise Linux Desktop 5 x86_64
  • Red Hat Enterprise Linux Desktop 5 i386
  • Red Hat Enterprise Linux for IBM z Systems 5 s390x
  • Red Hat Enterprise Linux for Power, big endian 5 ppc
  • Red Hat Enterprise Linux Server from RHUI 5 x86_64
  • Red Hat Enterprise Linux Server from RHUI 5 i386

Fixes

  • BZ - 240024 - Mod_proxy_http ProxyErrorOverride eating cookies
  • BZ - 240857 - [RFE] Apache does not report patch level when scanned
  • BZ - 241680 - logrotate.d/httpd postrotate must use initscripts
  • BZ - 245719 - mod_proxy configuration inheritance issue
  • BZ - 245763 - long lines incorrectly handled by Apache's logresolve
  • BZ - 250731 - CVE-2007-3847 httpd out of bounds read

CVEs

  • CVE-2007-3847

References

  • http://www.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 5

SRPM
httpd-2.2.3-11.el5.src.rpm SHA-256: 8d3ca45c0d26238130e00496dd810206cb0c1507febdbe7b9bb04658fd0e1049
x86_64
httpd-2.2.3-11.el5.x86_64.rpm SHA-256: 670317bb406a834ced622aff407c0dec722819ee9d213dbd2363597348ce2865
httpd-devel-2.2.3-11.el5.i386.rpm SHA-256: 5424097e6ba1f8d2bda6fe52d686de05ef6656b640b4ff14b477e8855493cc0f
httpd-devel-2.2.3-11.el5.x86_64.rpm SHA-256: 928fe27f1e8e0877ec1d2efbfc17981cc5ad7833c90874902ba833cbf23449f5
httpd-manual-2.2.3-11.el5.x86_64.rpm SHA-256: 378f78f8acd64250b95576c30f6b28ce276557965777209bc0f3bde7e9183c71
mod_ssl-2.2.3-11.el5.x86_64.rpm SHA-256: 0f5a08143fc045657bcbff318110316340ad0499c3ace1f473d4a203e9249302
ia64
httpd-2.2.3-11.el5.ia64.rpm SHA-256: 7c2b3c6e8944775fb3f70f8010889f863b13aaacbd5907fd820da154dd71e7af
httpd-devel-2.2.3-11.el5.ia64.rpm SHA-256: 140bb2ad4e05f8dfe8822021952e46049292991e8cab8a9531b4dd5fd96b3059
httpd-manual-2.2.3-11.el5.ia64.rpm SHA-256: 1e8575a395506f35ab13125c632ce2959c9d78a33580ef9f2aeeb27d4532881b
mod_ssl-2.2.3-11.el5.ia64.rpm SHA-256: 93cb71f9d8cc62aa87a88de5df6e52c376afb43e342fb1a49bcd80c9ee9a171c
i386
httpd-2.2.3-11.el5.i386.rpm SHA-256: 20a6593a4c6b7ab4a5aace5518325eb4d4c568de321930d1b211274882439dbe
httpd-devel-2.2.3-11.el5.i386.rpm SHA-256: 5424097e6ba1f8d2bda6fe52d686de05ef6656b640b4ff14b477e8855493cc0f
httpd-manual-2.2.3-11.el5.i386.rpm SHA-256: c1fa30d35d7182664e8d18b3261ceb2fb6bc390c861735c9b46cdceb9abec0b7
mod_ssl-2.2.3-11.el5.i386.rpm SHA-256: 107690cb96a597e0aa2ecdeb20f5011ad09d6d6a5433a7433cfaf15c7498a7d8

Red Hat Enterprise Linux Workstation 5

SRPM
httpd-2.2.3-11.el5.src.rpm SHA-256: 8d3ca45c0d26238130e00496dd810206cb0c1507febdbe7b9bb04658fd0e1049
x86_64
httpd-2.2.3-11.el5.x86_64.rpm SHA-256: 670317bb406a834ced622aff407c0dec722819ee9d213dbd2363597348ce2865
httpd-devel-2.2.3-11.el5.i386.rpm SHA-256: 5424097e6ba1f8d2bda6fe52d686de05ef6656b640b4ff14b477e8855493cc0f
httpd-devel-2.2.3-11.el5.x86_64.rpm SHA-256: 928fe27f1e8e0877ec1d2efbfc17981cc5ad7833c90874902ba833cbf23449f5
httpd-manual-2.2.3-11.el5.x86_64.rpm SHA-256: 378f78f8acd64250b95576c30f6b28ce276557965777209bc0f3bde7e9183c71
mod_ssl-2.2.3-11.el5.x86_64.rpm SHA-256: 0f5a08143fc045657bcbff318110316340ad0499c3ace1f473d4a203e9249302
i386
httpd-2.2.3-11.el5.i386.rpm SHA-256: 20a6593a4c6b7ab4a5aace5518325eb4d4c568de321930d1b211274882439dbe
httpd-devel-2.2.3-11.el5.i386.rpm SHA-256: 5424097e6ba1f8d2bda6fe52d686de05ef6656b640b4ff14b477e8855493cc0f
httpd-manual-2.2.3-11.el5.i386.rpm SHA-256: c1fa30d35d7182664e8d18b3261ceb2fb6bc390c861735c9b46cdceb9abec0b7
mod_ssl-2.2.3-11.el5.i386.rpm SHA-256: 107690cb96a597e0aa2ecdeb20f5011ad09d6d6a5433a7433cfaf15c7498a7d8

Red Hat Enterprise Linux Desktop 5

SRPM
httpd-2.2.3-11.el5.src.rpm SHA-256: 8d3ca45c0d26238130e00496dd810206cb0c1507febdbe7b9bb04658fd0e1049
x86_64
httpd-2.2.3-11.el5.x86_64.rpm SHA-256: 670317bb406a834ced622aff407c0dec722819ee9d213dbd2363597348ce2865
mod_ssl-2.2.3-11.el5.x86_64.rpm SHA-256: 0f5a08143fc045657bcbff318110316340ad0499c3ace1f473d4a203e9249302
i386
httpd-2.2.3-11.el5.i386.rpm SHA-256: 20a6593a4c6b7ab4a5aace5518325eb4d4c568de321930d1b211274882439dbe
mod_ssl-2.2.3-11.el5.i386.rpm SHA-256: 107690cb96a597e0aa2ecdeb20f5011ad09d6d6a5433a7433cfaf15c7498a7d8

Red Hat Enterprise Linux for IBM z Systems 5

SRPM
httpd-2.2.3-11.el5.src.rpm SHA-256: 8d3ca45c0d26238130e00496dd810206cb0c1507febdbe7b9bb04658fd0e1049
s390x
httpd-2.2.3-11.el5.s390x.rpm SHA-256: 2e4ececd171f8150ed69d0aa2d27eb791e7c37c16429d6c6407eb0e1650218ae
httpd-devel-2.2.3-11.el5.s390.rpm SHA-256: 84e797f55d53f18c66e6bd1dc3cd08be381e47bae3ffe194586a2990adf47ebe
httpd-devel-2.2.3-11.el5.s390x.rpm SHA-256: 2d253db86580aed3ef530b534eaedb41d441d8fecd929308f028fd225b06c42a
httpd-manual-2.2.3-11.el5.s390x.rpm SHA-256: 205c20f7eb64adab7b9c0b9bb9633718684d815bd8545ff63600c2644cf3f046
mod_ssl-2.2.3-11.el5.s390x.rpm SHA-256: 7ee7eea37e6fbe77e26b7dbd7fb1fe9d97b9a656591421f8ae0dd80f7cda2fa1

Red Hat Enterprise Linux for Power, big endian 5

SRPM
httpd-2.2.3-11.el5.src.rpm SHA-256: 8d3ca45c0d26238130e00496dd810206cb0c1507febdbe7b9bb04658fd0e1049
ppc
httpd-2.2.3-11.el5.ppc.rpm SHA-256: 0f026e5b727d3bdce8fa147c70d2f2f8ce4a04575ecf4c018ea4d6772bb1cfab
httpd-devel-2.2.3-11.el5.ppc.rpm SHA-256: 0da7cd77f3f09fd14b56db901228a24df3e506ee5f49c9d6964c9ab7a5778cc2
httpd-devel-2.2.3-11.el5.ppc64.rpm SHA-256: 3183d9c3c9fdd1abaaf6af327055c2ef94789a93e716ba87862d045f51f11762
httpd-manual-2.2.3-11.el5.ppc.rpm SHA-256: b95c21bfc994b346c0239b068becf8295801da7cf14cae0047fee8001d9c95f9
mod_ssl-2.2.3-11.el5.ppc.rpm SHA-256: fd6e50a78896302fd5063f1a6495abacad54e1f58d7c49caf803f37cc569e72b

Red Hat Enterprise Linux Server from RHUI 5

SRPM
httpd-2.2.3-11.el5.src.rpm SHA-256: 8d3ca45c0d26238130e00496dd810206cb0c1507febdbe7b9bb04658fd0e1049
x86_64
httpd-2.2.3-11.el5.x86_64.rpm SHA-256: 670317bb406a834ced622aff407c0dec722819ee9d213dbd2363597348ce2865
httpd-devel-2.2.3-11.el5.i386.rpm SHA-256: 5424097e6ba1f8d2bda6fe52d686de05ef6656b640b4ff14b477e8855493cc0f
httpd-devel-2.2.3-11.el5.x86_64.rpm SHA-256: 928fe27f1e8e0877ec1d2efbfc17981cc5ad7833c90874902ba833cbf23449f5
httpd-manual-2.2.3-11.el5.x86_64.rpm SHA-256: 378f78f8acd64250b95576c30f6b28ce276557965777209bc0f3bde7e9183c71
mod_ssl-2.2.3-11.el5.x86_64.rpm SHA-256: 0f5a08143fc045657bcbff318110316340ad0499c3ace1f473d4a203e9249302
i386
httpd-2.2.3-11.el5.i386.rpm SHA-256: 20a6593a4c6b7ab4a5aace5518325eb4d4c568de321930d1b211274882439dbe
httpd-devel-2.2.3-11.el5.i386.rpm SHA-256: 5424097e6ba1f8d2bda6fe52d686de05ef6656b640b4ff14b477e8855493cc0f
httpd-manual-2.2.3-11.el5.i386.rpm SHA-256: c1fa30d35d7182664e8d18b3261ceb2fb6bc390c861735c9b46cdceb9abec0b7
mod_ssl-2.2.3-11.el5.i386.rpm SHA-256: 107690cb96a597e0aa2ecdeb20f5011ad09d6d6a5433a7433cfaf15c7498a7d8

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • openshift.com
  • developers.redhat.com
  • connect.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2018 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter Facebook Google+