PT-2009-6634 · Apache+2 · Apache Http Server+2

Philip Pickett

·

Published

2009-12-09

·

Updated

2024-06-15

·

CVE-2010-0434

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.x before 2.2.15
Description The issue is related to the ap read request function in the Apache HTTP Server, specifically when a multithreaded MPM is used. It does not properly handle headers in subrequests under certain circumstances, potentially allowing remote attackers to obtain sensitive information via a crafted request. This could trigger access to memory locations associated with an earlier request.
Recommendations For Apache HTTP Server versions 2.2.x before 2.2.15, update to version 2.2.15 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0434
DSA-2035-1
HPSBUX02531
OPENSUSE-SU-2024:10268-1
RHSA-2010:0168
RHSA-2010:0175
RHSA-2010:0396
RHSA-2010:0602
RHSA-2010_0168
RHSA-2010_0175

Affected Products

Apache Http Server
Hp-Ux
Red Hat