According to David Wagner, iDEFENSE and the Apache HTTP Server
Project, several remotely exploitable vulnerabilities have been found
in the Apache package, a commonly used webserver. These
vulnerabilities could allow an attacker to enact a denial of service
against a server or execute a cross scripting attack. The Common
Vulnerabilities and Exposures (CVE) project identified the following
vulnerabilities:
1. CAN-2002-0839: A vulnerability exists on platforms using System V
shared memory based scoreboards. This vulnerability allows an
attacker who can execute under the Apache UID to exploit the Apache
shared memory scoreboard format and send a signal to any process as
root or cause a local denial of service attack.
2. CAN-2002-0840: Apache is susceptible to a cross site scripting
vulnerability in the default 404 page of any web server hosted on a
domain that allows wildcard DNS lookups.
3. CAN-2002-0843: There were some possible overflows in the utility
ApacheBench (ab) which...
Get the latest Linux and open source security news straight to your inbox.