First published: Thu Jan 12 2012(Updated: )
Apache 2.2 fixed a possible crash on shutdown if a child changes the sb_type field in the scoreboard. Since unprivileged children should not be able to affect the parent in this way, this is treated as a Low severity security issue [1]. The reporter has a nice writeup of the flaw as well [2]. [1] <a href="http://svn.apache.org/viewvc?view=revision&revision=1230065">http://svn.apache.org/viewvc?view=revision&revision=1230065</a> [2] <a href="http://www.halfdog.net/Security/2011/ApacheScoreboardInvalidFreeOnShutdown/">http://www.halfdog.net/Security/2011/ApacheScoreboardInvalidFreeOnShutdown/</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/httpd | <2.2.22 | 2.2.22 |
Apache HTTP server | >=2.0.0<2.0.65 | |
Apache HTTP server | >=2.2.0<2.2.22 | |
Debian Debian Linux | =5.0 | |
Debian Debian Linux | =6.0 | |
Debian Debian Linux | =7.0 | |
openSUSE openSUSE | =11.4 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Software Development Kit | =10-sp4 | |
Redhat Jboss Enterprise Web Server | =1.0.0 | |
Redhat Enterprise Linux | =5.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Storage | =2.0 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Eus | =6.2 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server Aus | =6.2 | |
Redhat Enterprise Linux Workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.