|
mod_gzip Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA8928
|
|
|
Release Date:
|
2003-06-03
|
|
Popularity:
|
5,116 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Privilege escalation System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Partial Fix
|
|
| Software: | mod_gzip 1.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: Multiple vulnerabilities have been identified in mod_gzip possibly allowing malicious people to gain system access.
The problems only occur when mod_gzip is configured to run in debug mode.
It is possible to cause a buffer overflow by requesting a filename longer than 2048 characters.
A format string vulnerability exist in the handling of log entries. This is exploitable if Apache log is enabled.
When Apache log isn't used, mod_gzip logs to "/tmp" in an insecure way allowing a race condition.
Solution: Do not use mod_gzip in debug mode on production sites.
Provided and/or discovered by: Matthew Murphy
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|