CVE-2010-0434
CVE-2010-0434
The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlhttp://lists.vmware.com/pipermail/security-announce/2010/000105.htmlhttp://marc.info/?l=bugtraq&m=127557640302499&w=2https://bugzilla.redhat.com/show_bug.cgi?id=570171http://secunia.com/advisories/39100http://secunia.com/advisories/39115http://secunia.com/advisories/39501http://secunia.com/advisories/39628