VULNERABILIDADES. Nuevas variantes en vulnerabilidades que afectan al servidor Apache

Noviembre 2, 2009

NUEVA VULNERABILIDAD, Apache HTTP Server Solaris Event Port Pollset Support Remote Denial Of Service Vulnerability

Octubre 6, 2009

Apache HTTP Server is prone to a denial-of-service vulnerability because of faulty error handling.

Successful exploits may allow remote attackers to trigger denial-of-service conditions.

This issue affects versions prior to Apache 2.2.14 on Solaris platforms.

Published:    Oct 05 2009 12:00AM
Updated:       Oct 06 2009 12:39AM

REFERENCIA DE LA VULNERABILIDAD

fuente: securityfocus.com

apache


VULNERABILIDADES. Nuevas variantes que afectan a Apache Tomcat

Septiembre 22, 2009

NUEVAS VULNERABILIDADES, que afectan al mod_proxy de Apache.

Septiembre 4, 2009

Dos nuevas vulnerabilidades que afectan al mod_proxy de Apache.

Published:     Sep 03 2009 12:00AM
Updated:        Sep 03 2009 09:42PM


REFERENCIA APACHE MODULE mod_proxy_ftp HOMEPAGE

fuente: securityfocus.com

apache


NUEVA VULNERABILIDAD. Apache APR-util ‘xml/apr_xml.c’ Denial of Service Vulnerability

Julio 6, 2009

Apache ‘APR-util’ is prone to a vulnerability that may allow attackers to cause an affected application to consume memory, resulting in a denial-of-service condition.

Versions prior to ‘APR-util’ 1.3.7 are vulnerable.

Published:       Jun 06 2009 12:00AM
Updated:            Jul 06 2009 08:29AM

REFERENCIA DE LA VULNERABILIDAD

REFERENCIA DEL FABRICANTE

fuente: securityfocus.com

apache-tomcat_logo_nomatte



VULNERABILIDAD. Multples vulnerabilidades que afectan al servidor Tomcat de Apache

Febrero 24, 2009

VULNERABILIDADES. Nuevas vulnerabilidades para el mod_proxy del servidor web Apache.

Diciembre 16, 2008

VULNERABILIDAD. Apache mod_imagemap and mod_imap Cross-Site Scripting Vulnerability

Noviembre 20, 2008

Apache is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This issue affects the following:

- The ‘mod_imagemap’ module in Apache 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, and 2.2.0

- The ‘mod_imap’ module in Apache 1.3.39, 1.3.37, 1.3.36, 1.3.35, 1.3.34, 1.3.33, 1.3.32, 1.3.31, 1.3.29, 1.3.28, 1.3.27, 1.3.26, 1.3.24, 1.3.22, 1.3.20, 1.3.19, 1.3.17, 1.3.14, 1.3.12, 1.3.11, 1.3.9, 1.3.6, 1.3.4, 1.3.3, 1.3.2, 1.3.1, and 1.3.0.

fuente: securityfocus

REFERENCIA DE LA VULNERABILIDAD

apache2


VULNERABILIDAD. Apache HTTP Server 2.2.6, 2.0.61 and 1.3.39 ‘mod_status’ Cross-Site Scripting Vulnerability

Noviembre 20, 2008

The Apache HTTP Server ‘mod_status’ module is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. Reportedly, attackers can also use this issue to redirect users’ browsers to arbitrary locations, which may aid in phishing attacks.

The issue affects versions prior to Apache 2.2.7-dev, 2.0.62-dev, and 1.3.40-dev.

fuente: securityfocus

REFERENCIA DE LA VULNERABILIDAD

apache3


VULNERABILIDAD. Apache ‘mod_proxy_http’ Interim Response Denial of Service Vulnerability

Noviembre 12, 2008

The Apache ‘mod_proxy_http’ module is prone to a denial-of-service vulnerability that affects the processing of interim responses.

Attackers may exploit this issue to cause denial-of-service conditions.

Reportedly, the issue affects Apache 2.2.8 and 2.0.63; other versions may also be affected.

fuente: securityfocus

REFERENCIA DE LA VULNERABILIDAD

apache1


VULNERABILIDAD. Apache ‘mod_proxy_ftp’ Wildcard Characters Cross-Site Scripting Vulnerability

Noviembre 12, 2008

The Apache ‘mod_proxy_ftp’ module is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input.

An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.

This issue is reported to affect Apache 2.0.63 and 2.2.9; other versions may also be affected.

fuente: securityfocus

REFERENCIA DE LA VULNERABILIDAD

apache