Apache HTTP Server `httpOnly´ Multiple Vulnerabilities
Last Update Date:
22 May 2012
Release Date:
30 Jan 2012
5520
Views
RISK: Medium Risk
TYPE: Servers - Web Servers
Multiple vulnerabilities have been identified in Apache HTTP Server, which can be exploited by malicious people to disclose potentially sensitive information and cause a DoS (Denial of Service).
- An error when handling the "%{cookiename}C" log format string when using a threaded MPM can be exploited to cause a crash by sending a specially crafted cookie.
- An error within the default error response for status code 400 when no custom ErrorDocument is configured can be exploited to expose "httpOnly" cookies.
Impact
- Denial of Service
- Information Disclosure
System / Technologies affected
- Apache 2.2.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://httpd.apache.org/security/vulnerabilities_22.html
Vulnerability Identifier
Source
Related Link
Share with