LWN.net Logo

httpd: information disclosure

Package(s):httpd CVE #(s):CVE-2010-2791
Created:August 30, 2010 Updated:October 18, 2010
Description: From the Red Hat advisory:

A flaw was discovered in the way the mod_proxy module of the Apache HTTP Server handled the timeouts of requests forwarded by a reverse proxy to the back-end server. If the proxy was configured to reuse existing back-end connections, it could return a response intended for another user under certain timeout conditions, possibly leading to information disclosure.

Alerts:
rPath rPSA-2010-0060-1 2010-10-17
CentOS CESA-2010:0659 2010-08-31
Red Hat RHSA-2010:0659-01 2010-08-30
Gentoo 201206-25 2012-06-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds