Serious flaw discovered in Apache

 

IT admins warned to upgrade immediately.

Security researchers have warned of a serious flaw in the Apache web server software that could allow hackers to gain system privileges.

The flaw is found in Apache 2.2.14 and earlier versions where the software is being run on Windows systems, but the latest version 2.2.15 fixes the exploit. Users are advised to upgrade immediately.

"By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory," said the advisory from Sense of Security.

"However, function pointers still remain in memory and are called when published ISAPI functions are referenced. This results in a dangling pointer vulnerability."

Proof-of-concept code for the attack has already been produced, in which a sos.txt file is sent to the system and is available for download.

Copyright ©v3.co.uk


Serious flaw discovered in Apache
"Grr .. I had to pay for a remote reboot when I accidentally halted one of our servers one day - the remote reboot mechanism apparently doesn't work in that case :-/ I'll never live that one down. ..."
By Sams
 
 
 
Comments: 3
Sams
Mar 10, 2010 8:53 AM
Luckily we don't run Windows servers ... oh wait .. it isn't luck.
Res
Mar 10, 2010 10:05 AM
LOL @ Sams, I agree. However windows servers are good for colo business, nice remote hands income for all the reboot *chuckles*
Sams
Mar 10, 2010 12:26 PM
Grr .. I had to pay for a remote reboot when I accidentally halted one of our servers one day - the remote reboot mechanism apparently doesn't work in that case :-/ I'll never live that one down. It's been a long time since I've had to reboot due to anything other than kernel upgrades. It is not uncommon to see 100+ days between reboots on our servers.
Comments have been disabled for this article.
 
 
 
Top Stories
iTnews on tour: The Executive Summit Series
Join us in Sydney and Melbourne to meet Australia's tech leaders.
 
NBN Co braces for secrecy probe
Opinion: Is commercial sensitivity a catch-all?
 
Exclusive: NBN Co withholds fibre upgrade price
Fears trial details could breach contractor confidentiality.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Was your 2012 IT budget...




   |   View results
Cut by less than ten percent?
  17%
 
Cut by more than ten percent?
  34%
 
Flat
  26%
 
Increased by less than ten percent?
  7%
 
Increased by more than ten percent?
  15%
TOTAL VOTES: 350

Vote
Will you still use DropBox and other cloud storage in the wake of the Megauploads saga?

   |   View results
Yes
  63%
 
No
  37%
TOTAL VOTES: 230

Vote