Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, allows local users to gain privileges via a .htaccess file with a crafted SetEnvIf directive, in conjunction with a crafted HTTP request header, leading to a heap-based buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.0.61 | 2.0.61 |
Http_server | Apache | 2.0.58 | 2.0.58 |
Http_server | Apache | 2.0.53 | 2.0.53 |
Http_server | Apache | 2.0.52 | 2.0.52 |
Http_server | Apache | 2.0.44 | 2.0.44 |
Http_server | Apache | 2.0.59 | 2.0.59 |
Http_server | Apache | 2.0.32 | 2.0.32 |
Http_server | Apache | 2.0.32 | 2.0.32 |
Http_server | Apache | 2.0.41 | 2.0.41 |
Http_server | Apache | 2.0.40 | 2.0.40 |
Http_server | Apache | 2.0.55 | 2.0.55 |
Http_server | Apache | 2.0.54 | 2.0.54 |
Http_server | Apache | 2.0.42 | 2.0.42 |
Http_server | Apache | 2.0.64 | 2.0.64 |
Http_server | Apache | 2.0.47 | 2.0.47 |
Http_server | Apache | 2.0.56 | 2.0.56 |
Http_server | Apache | 2.0.50 | 2.0.50 |
Http_server | Apache | 2.0.35 | 2.0.35 |
Http_server | Apache | 2.0.37 | 2.0.37 |
Http_server | Apache | 2.0.39 | 2.0.39 |
Http_server | Apache | 2.0.57 | 2.0.57 |
Http_server | Apache | 2.0.51 | 2.0.51 |
Http_server | Apache | 2.0.28 | 2.0.28 |
Http_server | Apache | 2.0.63 | 2.0.63 |
Http_server | Apache | 2.0.49 | 2.0.49 |
Http_server | Apache | 2.0.9 | 2.0.9 |
Http_server | Apache | 2.0.34 | 2.0.34 |
Http_server | Apache | 2.0.38 | 2.0.38 |
Http_server | Apache | 2.0.48 | 2.0.48 |
Http_server | Apache | 2.0.45 | 2.0.45 |
Http_server | Apache | 2.0.36 | 2.0.36 |
Http_server | Apache | 2.0.46 | 2.0.46 |
Http_server | Apache | 2.0.43 | 2.0.43 |
Http_server | Apache | 2.0.28 | 2.0.28 |
Http_server | Apache | 2.0 | 2.0 |
Http_server | Apache | 2.0.60 | 2.0.60 |
Red Hat Enterprise Linux 5 | RedHat | httpd-0:2.2.3-63.el5_8.1 | * |
Red Hat Enterprise Linux 6 | RedHat | httpd-0:2.2.15-15.el6_2.1 | * |
Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | RedHat | httpd-0:2.2.17-15.4.ep5.el5 | * |
Red Hat JBoss Enterprise Web Server 1 for RHEL 6 | RedHat | httpd-0:2.2.17-15.4.ep5.el6 | * |
Red Hat JBoss Web Server 1.0 | RedHat | * | |
Apache2 | Ubuntu | hardy | * |
Apache2 | Ubuntu | lucid | * |
Apache2 | Ubuntu | maverick | * |
Apache2 | Ubuntu | natty | * |
Apache2 | Ubuntu | oneiric | * |
Apache2 | Ubuntu | upstream | * |