VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2068
http_server: mod_proxy_http.c in mod_proxy_http in the Apache HT...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2068

Original

mod_proxy_http.c in mod_proxy_http in the Apache HTTP Server 2.2.9 through 2.2.15, 2.3.4-alpha, and 2.3.5-alpha on Windows, NetWare, and OS/2, in certain configurations involving proxy worker pools, does not properly detect timeouts, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-06-18
Source Information Category:
Advisory, Alert
Last Updated:
2010-06-21




Affected Product Tags
cpe:/a:apache:http_server:2.2.10
cpe:/a:apache:http_server:2.2.11
cpe:/a:apache:http_server:2.2.12
cpe:/a:apache:http_server:2.2.13
cpe:/a:apache:http_server:2.2.14
cpe:/a:apache:http_server:2.2.15
cpe:/a:apache:http_server:2.2.9
cpe:/a:apache:http_server:2.3.4:alpha
cpe:/a:apache:http_server:2.3.5:alpha
cpe:/o:ibm:os2
cpe:/o:microsoft:windows
cpe:/o:novell:netware
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
X Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
X Partial [?]
Complete [?]

[Integrity Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

[Availability Impact]  [?]
Undefined [?]

X None [?]
Partial [?]
Complete [?]

Alternatives




References
BID 40827




BUGTRAQ 20100611 [advisory] httpd Timeout detection flaw (mod_proxy_http) CVE-2010-2068




CONFIRM http://www.apache.org/dist/httpd/patches/apply_to_2.3.5/CVE-2010-2068-r953418.patch




CONFIRM http://www.apache.org/dist/httpd/patches/apply_to_2.2.15/CVE-2010-2068-r953616.patch




CONFIRM http://httpd.apache.org/security/vulnerabilities_22.html




MLIST [httpd-announce] 20100611 [advisory] httpd Timeout detection flaw (mod_proxy_http) CVE-2010-2068




SECTRACK 1024096




SECUNIA 40206




VUPEN ADV-2010-1436




Vulnerability Type Information Leak / Disclosure (CWE-200)




XF apache-modproxyhttp-timeout-info-disc(59413)





Copyright © 2010 JPCERT/CC All Rights Reserved.