Gentoo Security Advisory GLSA 200406-05 (Apache)

Summary
The remote host is missing updates announced in advisory GLSA 200406-05.
Solution
Apache 1.x users should upgrade to the latest version of mod_ssl: # emerge sync # emerge -pv '>=net-www/mod_ssl-2.8.18' # emerge '>=net-www/mod_ssl-2.8.18' Apache 2.x users should upgrade to the latest version of Apache: # emerge sync # emerge -pv '>=net-www/apache-2.0.49-r3' # emerge '>=net-www/apache-2.0.49-r3' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200406-05 http://bugs.gentoo.org/show_bug.cgi?id=51368
Insight
A bug in mod_ssl may allow a remote attacker to execute remote code when Apache is configured a certain way.