The IT security firm Sense of Security has issued a security advisory concerning a serious exploit it has discovered in the popular open source web server Apache.
"By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory. However function pointers still remain in memory and are called when published ISAPI functions are referenced. This results in a dangling pointer vulnerability. Successful exploitation results in the execution of arbitrary code with SYSTEM privileges."
Sharing is Caring:
0 comments:
Post a Comment