PT-2014-9136 · Apache · Apache-Mod Wsgi

Publicado

2014-08-08

·

Atualizado

2014-08-08

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions apache-mod wsgi versions prior to 4.2.4
Description The issue is related to an off-by-one error in applying a limit to the number of supplementary groups allowed for a daemon process group. This could lead to memory corruption or a process crash if more groups than the operating system allowed were specified to the supplementary-groups option.
Recommendations For versions prior to 4.2.4, update to version 4.2.4 or later to resolve the issue. As a temporary workaround, consider restricting the number of supplementary groups to prevent memory corruption or process crashes.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

MGASA-2014-0323

Produtos afetados

Apache-Mod Wsgi