Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-0425

Опубликовано: 05 мар. 2010
Источник: ubuntu
Приоритет: low
EPSS Критический
CVSS2: 10

Описание

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

РелизСтатусПримечание
dapper

not-affected

2.3.x, Windows-only
devel

not-affected

2.3.x, Windows-only
hardy

not-affected

2.3.x, Windows-only
intrepid

not-affected

2.3.x, Windows-only
jaunty

not-affected

2.3.x, Windows-only
karmic

not-affected

2.3.x, Windows-only
upstream

released

2.3.7

Показывать по

Ссылки на источники

EPSS

Процентиль: 100%
0.94248
Критический

10 Critical

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

debian
больше 16 лет назад

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server ...

github
больше 4 лет назад

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

suse-cvrf
почти 9 лет назад

Security update for apache2

EPSS

Процентиль: 100%
0.94248
Критический

10 Critical

CVSS2