All the latest UK technology news, reviews and analysis

Serious flaw discovered in Apache

by Iain Thomson

More from this author

09 Mar 2010

Be the first to comment

  • Tweet this
Apache
The flaw is found in Apache 2.2.14 and earlier versions

Security researchers have warned of a serious flaw in the Apache web server software that could allow hackers to gain system privileges.

The flaw is found in Apache 2.2.14 and earlier versions where the software is being run on Windows systems, but the latest version 2.2.15 fixes the exploit. Users are advised to upgrade immediately.

"By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory," said the advisory from Sense of Security.

"However, function pointers still remain in memory and are called when published ISAPI functions are referenced. This results in a dangling pointer vulnerability."

Proof-of-concept code for the attack has already been produced, in which a sos.txt file is sent to the system and is available for download.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Web C# ASP.NET Developer (Equity or Mutual Funds) London

Web C# ASP.NET Developer (Equity or Mutual Funds) London...

Senior Exploratory Tester - Selenium, Java, AJAX, WEB

Senior Exploratory Tester - Selenium, Java, AJAX, WEB...

SQL DBA/ Data Architect (T-SQL, SSIS, ETL) - Derivatives

SQL DBA/ Data Architect (T-SQL, SSIS, ETL) - Derivatives...

Test Analyst (Web, QTP, VB.NET, SQL) Wolverhampton

Test Analyst (Web, QTP, Test Director, VB.NET, SQL...

To send to more than one email address, simply separate each address with a comma.