Jump to content

Serious flaw discovered in Apache


nsane.forums

Recommended Posts

nsane.forums

medium.gif

IT admins warned to upgrade immediately

Security researchers Sense of Security are warning of a serious flaw in the Apache web server software that could allow hackers to gain system privileges.

The flaw is found in Apache 2.2.14 and earlier versions where the software is being run on Windows systems, but the latest version 2.2.15 fixes the exploit. Users are advised to upgrade immediately.

"By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory," the advisory warns.

"However function pointers still remain in memory and are called when published ISAPI functions are referenced. This results in a dangling pointer vulnerability."

Proof of concept code for the attack has already been produced, where a sos.txt file is sent to the system and is available for download.

view.gif View: Original Article

Link to comment
Share on other sites


  • Views 737
  • Created
  • Last Reply

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...