CVE-2002-0839
CVE-2002-0839
The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not normally be allowed, by modifying the parent[].pid and parent[].last_rtime segments in the scoreboard.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
ftp://patches.sgi.com/support/free/security/advisories/20021105-01-Ihttp://archives.neohapsis.com/archives/bugtraq/2002-10/0195.htmlhttp://archives.neohapsis.com/archives/bugtraq/2002-10/0254.htmlhttp://archives.neohapsis.com/archives/vulnwatch/2002-q4/0012.htmlhttp://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000530http://marc.info/?l=apache-httpd-announce&m=103367938230488&w=2http://marc.info/?l=bugtraq&m=103376585508776&w=2http://marc.info/?l=bugtraq&m=130497311408250&w=2http://online.securityfocus.com/advisories/4617https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E