11 Jun 2010 21:49
[advisory] httpd Timeout detection flaw (mod_proxy_http) CVE-2010-2068
William A. Rowe Jr. <wrowe <at> apache.org>
2010-06-11 19:49:17 GMT
2010-06-11 19:49:17 GMT
Vulnerability; httpd Timeout detection flaw (mod_proxy_http) CVE-2010-2068
Classification; important
Description;
A timeout detection flaw in the httpd mod_proxy_http module causes
proxied response to be sent as the response to a different request,
and potentially served to a different client, from the HTTP proxy
pool worker pipeline.
This may represent a confidential data revealing flaw.
This affects only Netware, Windows or OS2 builds of httpd version
2.2.9 through 2.2.15, 2.3.4-alpha and 2.3.5-alpha, when the proxy
worker pools have been enabled. Earlier 2.2, 2.0 and 1.3 releases
were not affected.
Acknowledgements;
We would like to thank Loren Anderson for the thorough research
and reporting of this flaw.
Mitigation;
Apply any one of the following mitigations to avert the possibility
of confidential information disclosure.
* Do not load mod_proxy_http.
(Continue reading)
RSS Feed