Thread Rating:
  • 2 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Apache web server bug grants root access on shared hosting environments
#1
Quote:This week, the Apache Software Foundation has patched a severe vulnerability in the Apache (httpd) web server project that could --under certain circumstances-- allow rogue server scripts to execute code with root privileges and take over the underlying server.
 
The vulnerability, tracked as CVE-2019-0211, affects Apache web server releases for Unix systems only, from 2.4.17 to 2.4.38, and was fixed this week with the release of version 2.4.39.
 
According to the Apache team, less-privileged Apache child processes (such as CGI scripts) can execute malicious code with the privileges of the parent process.
 
Because on most Unix systems Apache httpd runs under the root user, any threat actor who has planted a malicious CGI script on an Apache server can use CVE-2019-0211 to take over the underlying system running the Apache httpd process, and inherently control the entire machine.

SOURCE: https://www.zdnet.com/article/apache-web...ironments/
[-] The following 2 users say Thank You to silversurfer for this post:
  • Deep900, harlan4096
Reply
#2
It's good this has been fixed, Apache is widely used and this kind of bugs are really serious.
[-] The following 2 users say Thank You to Deep900 for this post:
  • harlan4096, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Qualcomm details Adreno X1 GPU: specs, p...
Qualcomm Adreno X1...harlan4096 — 06:03
The end of Windows 11's Recall AI featur...
When Copilot Plus ...harlan4096 — 06:01
Waterfox G6.0.16
Waterfox G6.0.16​ ...harlan4096 — 09:28
Opera 111 (111.0.5168.25)
Opera is thrilled ...harlan4096 — 09:26
HWiNFO 8.04
Latest v8.04​ R...harlan4096 — 09:25

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (37)Tedscolo
avatar (44)brakasig
avatar (43)JamesReshy
avatar (45)Francisemefe
avatar (38)leoniDup
avatar (37)Patrizaancem
avatar (37)biobdam
avatar (38)storoBox
avatar (46)kinotHeemn
avatar (37)Ceballos1976
avatar (38)efynu

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>