PT-2010-4294 · Apache+1 · Apache Http Server+1

Publicado

2010-07-23

·

Atualizado

2023-02-13

·

CVE-2010-2791

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server version 2.2.9
Description The issue is related to an information disclosure flaw in the mod proxy component of the Apache HTTP Server. When running on Unix platforms, if a timeout occurs while reading a response from a persistent connection, the backend connection is not closed. This allows remote attackers to potentially obtain sensitive responses intended for other clients under certain circumstances. The flaw is triggered by specific timeout conditions and affects configurations that use proxy worker pools.
Recommendations For Apache HTTP Server version 2.2.9, as a temporary workaround, consider globally configuring the server with the setting: SetEnv proxy-nokeepalive 1. This configuration change can help mitigate the risk of information disclosure until a more permanent fix is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2791
RHSA-2010:0659
RHSA-2010_0659

Produtos afetados

Apache Http Server
Red Hat