LWN.net Logo

apache: information leak

Package(s):apache CVE #(s):CVE-2010-0434
Created:March 8, 2010 Updated:April 12, 2011
Description: From the Mandriva advisory:

The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.

Alerts:
rPath rPSA-2011-0014-1 2011-04-11
rPath rPSA-2010-0056-1 2010-09-13
Fedora FEDORA-2010-6055 2010-04-09
Fedora FEDORA-2010-6131 2010-04-09
SuSE SUSE-SR:2010:010 2010-04-27
Debian DSA-2035-1 2010-04-17
Pardus 2010-45 2010-03-29
CentOS CESA-2010:0175 2010-03-28
CentOS CESA-2010:0168 2010-03-28
Red Hat RHSA-2010:0168-01 2010-03-25
Red Hat RHSA-2010:0175-01 2010-03-25
Ubuntu USN-908-1 2010-03-10
Mandriva MDVSA-2010:057 2010-03-06
Gentoo 201206-25 2012-06-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds