Jump to content

Advisories MDVSA-2010:057: apache


paul
 Share

Recommended Posts

A vulnerabilitiy has been found and corrected in apache:

 

The ap_read_request function in server/protocol.c in the Apache HTTP

Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does

not properly handle headers in subrequests in certain circumstances

involving a parent request that has a body, which might allow remote

attackers to obtain sensitive information via a crafted request that

triggers access to memory locations associated with an earlier request

(CVE-2010-0434).

 

Packages for 2008.0 are provided for Corporate Desktop 2008.0

customers.

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...