Security researchers have warned of a serious flaw in the Apache web server software that could allow hackers to gain system privileges.
The flaw is found in Apache 2.2.14 and earlier versions where the software is being run on Windows systems, but the latest version 2.2.15 fixes the exploit. Users are advised to upgrade immediately.
"By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory," said the advisory from Sense of Security.
"However, function pointers still remain in memory and are called when published ISAPI functions are referenced. This results in a dangling pointer vulnerability."
Proof-of-concept code for the attack has already been produced, in which a sos.txt file is sent to the system and is available for download.
Serious flaw discovered in Apache
By
Iain Thomson
on Mar 10, 2010 8:24AM

Got a news tip for our journalists? Share it with us anonymously here.
Partner Content
Ingram Micro Ushers in the Age of Ultra

Kaseya Dattocon APAC 2024 is Back

Secure, integrated platforms enable MSPs to focus bringing powerful solutions to customers

Tech For Good program gives purpose and strong business outcomes

Build cybersecurity capability with award winning Fortinet training from Ingram Micro
Sponsored Whitepapers
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan

Pulseway Essential Eight Framework

7 Best Practices For Implementing Human Risk Management

2025 State of Machine Identity Security Report