It is currently believed that this was introduced by? apache2 (2.2.14-5ubuntu8.6) lucid-security; urgency=low
* SECURITY UPDATE: Range header DoS vulnerability - debian/patches/207_CVE-2011-3192.dpatch: filter out large byte ranges and improve memory efficiency in handling buckets. (thanks to Debian and upstream) - CVE-2011-3192 * Include fix for regressions introduced by above patch: - debian/patches/208_CVE-2011-3192_regression.dpatch: return 206 and 416 response codes where appropriate (see deban bug 639825) -- Steve Beattie <sbeat...@ubuntu.com (sbeattie: 3910) > Thu, 01 Sep 2011 01:52:17 -0700 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2011-3192 ** Changed in: apache2 (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in Ubuntu. https://bugs.launchpad.net/bugs/839390 Title: Apache+Kerberos not working anymore since update today To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/839390/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs