CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / january, 2006 / Denial of service in Apache mod_ssl 

Denial of service in Apache mod_ssl

Denial of service in Apache mod_ssl

Madrid, January 9, 2006 - Security Tracker has reported a vulnerability in Apache mod_ssl, which could allow a remote attacker to crash the server.

The problem occurs when an SSL virtual host is configured with access control and custom 400 error document. An attacker could send a specially-crafted request to trigger a null pointer deference, which could cause the server to crash when using the multi-processing module.

Although Apache has not yet published a solution for this problem, some Linux distributions, like Red Hat Enterprise Linux, have released a fix for this problem.

More information about this flaw is available at: http://www.securitytracker.com/alerts/2006/Jan/1015447.html

Oxygen3 24h-365d
by Panda Software

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel