Mandriva Linux Security Advisory : apache (MDVSA-2010:057)

This script is Copyright (C) 2010-2016 Tenable Network Security, Inc.

Synopsis :

The remote Mandriva Linux host is missing one or more security

Description :

A vulnerability has been found and corrected in apache :

The ap_read_request function in server/protocol.c in the Apache HTTP
Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not
properly handle headers in subrequests in certain circumstances
involving a parent request that has a body, which might allow remote
attackers to obtain sensitive information via a crafted request that
triggers access to memory locations associated with an earlier request

Packages for 2008.0 are provided for Corporate Desktop 2008.0

The updated packages have been patched to correct this issue.

See also :

Solution :

Update the affected packages.

Risk factor :

Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : false

Family: Mandriva Local Security Checks

Nessus Plugin ID: 44997 (mandriva_MDVSA-2010-057.nasl)

Bugtraq ID: 38580

CVE ID: CVE-2010-0434

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now