LWN.net Logo

apache: remote attack via orphaned callback pointers

Package(s):httpd CVE #(s):CVE-2010-0425
Created:March 9, 2010 Updated:March 30, 2010
Description: From the CVE entry:

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.3.x before 2.3.7 on Windows does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which has unspecified impact and remote attack vectors related to "orphaned callback pointers."

Alerts:
Pardus 2010-45 2010-03-29
Slackware SSA:2010-067-01 2010-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds