Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Apache mod_cookies Buffer Overflow Vulnerability

The Apache Project is a collaborative software development effort aimed at creating a robust, commercial-grade, featureful, and freely-available source code implementation of an HTTP (Web) server. Certain versions of the Apache webserver shipped with a remotely exploitable buffer overflow attack. This overflow was present in the function make_cookie, in mod_cookies.c used a 100 byte buffer. Remote attackers, if they provided more than 100 bytes, could exploit this vulnerabiltity to gain access to the server running the Apache server.







 

Privacy Statement
Copyright 2009, SecurityFocus