Bug#534712: apache2.2-common: DOS possible with mod_deflate

2009-07-09 Thread Marc Deslauriers
This is CVE-2009-1891: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891 Upstream patch: http://svn.apache.org/viewvc?view=rev&revision=791454 -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists

Bug#534712: apache2.2-common: DOS possible with mod_deflate

2009-06-26 Thread François Guerraz
Package: apache2.2-common Version: 2.2.9-10+lenny3 Severity: normal Tags: patch security There is a bug in mod_deflate that can lead to a DOS with a very small network traffic. The problem is the following : when downloading a file with mod_deflate enabled and aborting the connexion before the en