Processed: your mail

2009-06-19 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

 clone 533661 -1
Bug#533661: slowloris denial-of-service vulnerability
Bug 533661 cloned as bug 533662.

 clone 533661 -2
Bug#533661: slowloris denial-of-service vulnerability
Bug 533661 cloned as bug 533663.

 clone 533661 -3
Bug#533661: slowloris denial-of-service vulnerability
Bug 533661 cloned as bug 533664.

 clone 533661 -4
Bug#533661: slowloris denial-of-service vulnerability
Bug 533661 cloned as bug 533665.

 reassign -1 apache
Bug#533662: slowloris denial-of-service vulnerability
Bug reassigned from package `apache2' to `apache'.

 found -1 1.3.24-4.1+etch1
Bug#533662: slowloris denial-of-service vulnerability
Bug marked as found in version 1.3.24-4.1+etch1.

 reassign -2 squid
Bug#533663: slowloris denial-of-service vulnerability
Bug reassigned from package `apache2' to `squid'.

 found -2 2.6.5-6etch4
Bug#533663: slowloris denial-of-service vulnerability
Bug marked as found in version 2.6.5-6etch4.

 reassign -3 squid3
Bug#533664: slowloris denial-of-service vulnerability
Bug reassigned from package `apache2' to `squid3'.

 found -3 3.0.PRE5-5+etch1
Bug#533664: slowloris denial-of-service vulnerability
Bug marked as found in version 3.0.PRE5-5+etch1.

 reassign -4 dhttpd
Bug#533665: slowloris denial-of-service vulnerability
Bug reassigned from package `apache2' to `dhttpd'.

 found -4 1.02a-16
Bug#533665: slowloris denial-of-service vulnerability
Bug marked as found in version 1.02a-16.

 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to debian-apache-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#533661: slowloris denial-of-service vulnerability

2009-06-19 Thread Michael S Gilbert
package: apache2
version: 2.2.3-4+etch6
severity: important
tags: security

hello,

this package is supposedly vulnerable to something called a
slowloris denial-of-service attack.  please check to see whether
this is a correct assessment.  see [1],[2] for more info.  thanks.

[1] http://ha.ckers.org/slowloris/
[2] http://www.securityfocus.com/archive/1/456339/30/0/threaded



-- 
To UNSUBSCRIBE, email to debian-apache-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org