UNIRAS ALERT - 34/04 - Vulnerability Issues with Apache 2.0.x

"Richie B." <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.announce
Message-ID <[email protected]>
I did not see this here yet.

1. Through the testing of Apache by using the Codenomicon HTTP Test 
Tool, the ASF Security
Team have discovered a bug in the apr-util library, which can lead to 
arbitrary code
execution.

2. SITIC have discovered that Apache suffers from a buffer overflow when 
expanding environment
variables in configuration files such as .htaccess and httpd.conf, 
leading to possible
privilege escalation.



http://www.uniras.gov.uk/l1/l2/l3/alerts2004/alert-3404.txt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.