Apache 2.0.x < 2.0.45 Multiple Vulnerabilities (DoS, File Write)
Medium Nessus Plugin ID 11507
SynopsisThe remote web server is affected by multiple vulnerabilities.
DescriptionThe remote host is running a version of Apache 2.0.x that is prior to 2.0.45. It is, therefore, reportedly affected by multiple vulnerabilities :
- There is a denial of service attack that could allow an attacker to disable this server remotely.
- The httpd process leaks file descriptors to child processes, such as CGI scripts. An attacker who has the ability to execute arbitrary CGI scripts on this server (including PHP code) would be able to write arbitrary data in the file pointed to (in particular, the log files).
SolutionUpgrade to Apache web server version 2.0.45 or later.