Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-8109

Опубликовано: 29 дек. 2014
Источник: ubuntu
Приоритет: low
CVSS2: 4.3

Описание

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.

РелизСтатусПримечание
devel

released

2.4.10-8ubuntu3
esm-infra-legacy/trusty

not-affected

code not built
lucid

not-affected

2.2.14-5ubuntu8.14
precise

not-affected

2.2.22-1ubuntu1.7
trusty

not-affected

code not built
trusty/esm

not-affected

code not built
upstream

released

2.4.10-9
utopic

released

2.4.10-1ubuntu1.1

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.

nvd
около 11 лет назад

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.

debian
около 11 лет назад

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2. ...

github
больше 3 лет назад

mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.

suse-cvrf
почти 11 лет назад

Security update for apache2

4.3 Medium

CVSS2