Apache
The flaw is found in Apache 2.2.14 and earlier versions

Serious flaw discovered in Apache

IT admins warned to upgrade immediately

Iain Thomson in San Francisco

Security researchers have warned of a serious flaw in the Apache web server software that could allow hackers to gain system privileges.

The flaw is found in Apache 2.2.14 and earlier versions where the software is being run on Windows systems, but the latest version 2.2.15 fixes the exploit. Users are advised to upgrade immediately.

"By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory," said the advisory from Sense of Security.

"However, function pointers still remain in memory and are called when published ISAPI functions are referenced. This results in a dangling pointer vulnerability."

Proof-of-concept code for the attack has already been produced, in which a sos.txt file is sent to the system and is available for download.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Computer code

Open source bugs fixed quicker than commercial software

Veracode stats reveal around three-quarters of software does not meet an acceptable level of security

Microsoft

Microsoft confirms zero-day flaw in IIS

Vulnerability in FTP service in IIS versions 5.0, 5.1 and 6.0

Apache site hacked

Top web server provider suffers breach of systems

Microsoft releases code under General Public Licence

U-turn from Redmond pleases open source community

Related white papers

Related jobs

Most watched

Nokia N8

Nokia N8 video demo

Handset maker gives an early look at its first Symbian^3 smartphone

Motorola Milestone 2

Motorola Milestone 2 video demo

Android 2.2 comes to Milestone line

Analysis and Reports

Best practices to secure and protect backup data
Exploding the myths about data security and backup encryption

Using data integration to drive down costs and increase profits
This paper outlines why data integration is an important weapon in an enterprise’s competitive arsenal

Poll

VMworld 2010 poll

VMworld 2010 poll

How advanced is your firm's cloud computing strategy?

View poll results

White paper library

Attachmate

Smartstream

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Digital Britain

Innovation key to UK broadband take-up

Services like Project Canvas are vital, say experts

Amazon Kindle 3

Amazon Kindle 3 e-book reader review

Amazon trims the size and price of its newest Kindle,...

sas logo

SAS offers easy-to-use predictive analytics

Rapid Predictive Modeler designed to aid enterprise decision making

First impressions of Huawei's Ideos handset

Huawei's Ideos smartphone, announced today , is claimed by the...

Primary Navigation