Madrid, January 9, 2006 - Security Tracker has reported a vulnerability in Apache mod_ssl, which could allow a remote attacker to crash the server.
The problem occurs when an SSL virtual host is configured with access control and custom 400 error document. An attacker could send a specially-crafted request to trigger a null pointer deference, which could cause the server to crash when using the multi-processing module.
Although Apache has not yet published a solution for this problem, some Linux distributions, like Red Hat Enterprise Linux, have released a fix for this problem.
More information about this flaw is available at: http://www.securitytracker.com/alerts/2006/Jan/1015447.html
Oxygen3 24h-365d
by Panda Software
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel