First published: Thu Jan 12 2012(Updated: )
Apache 2.2 fixed a possible crash on shutdown if a child changes the sb_type field in the scoreboard. Since unprivileged children should not be able to affect the parent in this way, this is treated as a Low severity security issue [1]. The reporter has a nice writeup of the flaw as well [2]. [1] <a href="http://svn.apache.org/viewvc?view=revision&revision=1230065">http://svn.apache.org/viewvc?view=revision&revision=1230065</a> [2] <a href="http://www.halfdog.net/Security/2011/ApacheScoreboardInvalidFreeOnShutdown/">http://www.halfdog.net/Security/2011/ApacheScoreboardInvalidFreeOnShutdown/</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/httpd | <2.2.22 | 2.2.22 |
Apache Http Server | >=2.0.0<2.0.65 | |
Apache Http Server | >=2.2.0<2.2.22 | |
Debian | =5.0 | |
Debian | =6.0 | |
Debian | =7.0 | |
openSUSE | =11.4 | |
SUSE Linux Enterprise Server | =10-sp4 | |
SUSE Linux Enterprise Software Development Kit | =10-sp4 | |
Red Hat JBoss Enterprise Web Server | =1.0.0 | |
Red Hat Enterprise Linux | =5.0 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Storage | =2.0 | |
redhat enterprise Linux desktop | =6.0 | |
redhat enterprise Linux eus | =6.2 | |
redhat enterprise Linux server | =6.0 | |
redhat enterprise Linux server aus | =6.2 | |
redhat enterprise Linux workstation | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0031 is classified as a Low severity security issue.
To fix CVE-2012-0031, upgrade Apache HTTP Server to version 2.2.22 or later.
CVE-2012-0031 affects Apache HTTP Server versions below 2.2.22, and various versions of Red Hat, Debian, and openSUSE distributions.
No, CVE-2012-0031 is not a remote code execution vulnerability but rather a potential crash issue on shutdown.
No, unprivileged users should not be able to affect the parent process, which is a factor in the low severity classification of CVE-2012-0031.