Get a Pentest and security assessment of your IT network.

Advisories

Mandriva Linux Security Advisory 2007.140

Mandriva Linux Security Advisory – A vulnerability was discovered in the the Apache mod_status module that could lead to a cross-site scripting attack on sites where the server-status page was publically accessible and ExtendedStatus was enabled. A vulnerability was found in the Apache mod_cache module that could cause the httpd server child process to crash if it was sent a carefully crafted request. This could lead to a denial of service if using a threaded MPM. The Apache server also did not verify that a process was an Apache child process before sending it signals. A local attacker with the ability to run scripts on the server could manipulate the scoreboard and cause arbitrary processes to be terminated.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/57505/MDKSA-2007-140.txt

Source: https://packetstormsecurity.com/files/57505/Mandriva-Linux-Security-Advisory-2007.140.html

Related posts
Advisories

Secunia Security Advisory 15646

Advisories

Secunia Security Advisory 18761

Advisories

deluxeBBflaws.txt

Advisories

Mandriva Linux Security Advisory 2007.061