Apache Mod_TCL Remote Format String Vulnerability

Apache mod_tcl is prone to a remote format-string vulnerability because the application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-printing function.

Successfully exploiting this issue allows remote attackers to execute arbitrary machine code in the context of webserver processes running the affected Apache module. This facilitates the remote compromise of affected computers.

Apache mod_tcl version 1.0 is vulnerable to this issue.


 

Privacy Statement
Copyright 2010, SecurityFocus