|
|
| |
|
| |
apache: information leak
| Package(s): | apache |
CVE #(s): | CVE-2010-0434
|
| Created: | March 8, 2010 |
Updated: | April 12, 2011 |
| Description: |
From the Mandriva advisory:
The ap_read_request function in server/protocol.c in the Apache HTTP
Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does
not properly handle headers in subrequests in certain circumstances
involving a parent request that has a body, which might allow remote
attackers to obtain sensitive information via a crafted request that
triggers access to memory locations associated with an earlier request. |
| Alerts: |
|
( Log in to post comments)
|
|
|