PT-2014-9136 · Apache · Apache-Mod Wsgi
Publicado
2014-08-08
·
Atualizado
2014-08-08
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions
apache-mod wsgi versions prior to 4.2.4
Description
The issue is related to an off-by-one error in applying a limit to the number of supplementary groups allowed for a daemon process group. This could lead to memory corruption or a process crash if more groups than the operating system allowed were specified to the supplementary-groups option.
Recommendations
For versions prior to 4.2.4, update to version 4.2.4 or later to resolve the issue. As a temporary workaround, consider restricting the number of supplementary groups to prevent memory corruption or process crashes.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache-Mod Wsgi