Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Apache Web Server Scoreboard Memory Segment Overwriting SIGUSR1 Sending Vulnerability

Apache is a freely available webserver for Unix and Linux variants, as well as Microsoft operating systems.

A vulnerability in the handling of the Apache scorecard has been reported. A user with the privileges of the Apache user could attach to an httpd process, and overwrite the parent[].pid and parent[].last_rtime shared memory segments. By overwriting these, a signal may be sent to an arbitrary process with administrative privileges.







 

Privacy Statement
Copyright 2008, SecurityFocus