Serious Apache server bug gives root to baddies in shared host environments

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+WAmoZ9DXm3j-B_LvGj9xTWJzDHYPStf1ZgtGyChMPTQ@mail.gmail.com>
'The Apache HTTP Server, the Internet’s most widely used Web server,
just fixed a serious vulnerability that makes it possible for
untrusted users or software to gain unfettered control of the machine
the software runs on.

CVE-2019-0211, as the vulnerability is indexed, is a local privilege
escalation, meaning it allows a person or software that already has
limited access to the Web server to elevate privileges to root. From
there, the attacker could do just about anything. The vulnerability
makes it possible for unprivileged scripts to overwrite sensitive
parts of a server’s memory, Charles Fol, the independent researcher
who discovered the bug, wrote in a blog post. A malicious script could
exploit the vulnerability to gain root.

The vulnerability poses the most risk inside Web-hosting facilities
that offer shared instances, in which a single physical machine serves
content for more than one website. Typically, such servers prevent an
administrator of one site from accessing other sites or from accessing
sensitive settings of the machine itself.'

-- source: https://arstechnica.com/information-technology/2019/04/serious-apache-server-bug-gives-root-to-baddies-in-shared-host-environments/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.