PT-2018-2725 · Apache+5 · Apache Http Server+6

Jan Ingvoldstad

·

Published

2018-08-26

·

Updated

2024-06-15

·

CVE-2011-2767

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions mod perl versions 2.0 through 2.0.10
Description The issue allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file. This is possible because there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users to run Perl code in the context of the user account that runs Apache HTTP Server processes. The vulnerability is related to code injection in the .htaccess file, which can be exploited by a remote attacker to execute arbitrary Perl code under the context of the user account running Apache HTTP Server processes.
Recommendations For mod perl versions 2.0 through 2.0.10, consider disabling the execution of Perl code in .htaccess files until a patch is available. Restrict access to the .htaccess file to minimize the risk of exploitation. Avoid using Perl code in .htaccess files for HTTP request processing until the issue is resolved.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1524
BDU:2019-01621
CESA-2018_2737
CVE-2011-2767
DLA-1507-1
MGASA-2018-0474
OPENSUSE-SU-2019:2549-1
OPENSUSE-SU-2019:2558-1
OPENSUSE-SU-2019_2549-1
OPENSUSE-SU-2024:10626-1
RHSA-2018:2737
RHSA-2018:2825
RHSA-2018:2826
RHSA-2018_2737
SUSE-SU-2019:3213-1
SUSE-SU-2019_3213-1
SUSE-SU-2020:14266-1
SUSE-SU-2020_14266-1
USN-3825-1
USN-3825-2

Affected Products

Alt Linux
Apache Http Server
Centos
Red Hat
Suse
Ubuntu
Mod Perl