PT-2006-4986 · Apache · Apache+1

Sparfell

·

Publicado

2006-10-16

·

Atualizado

2017-07-20

·

CVE-2006-4154

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache 2.x with mod tcl module 1.0
Description The issue allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set var function call in files tcl cmds.c and tcl core.c.
Recommendations For Apache 2.x with mod tcl module 1.0, consider disabling the set var function in tcl cmds.c and tcl core.c until a patch is available. Restrict access to the mod tcl module to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4154

Produtos afetados

Apache
Mod Tcl