Skip to main content

Apache HTTP Server `httpOnly´ Multiple Vulnerabilities

Last Update Date: 22 May 2012 Release Date: 30 Jan 2012 5520 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

Multiple vulnerabilities have been identified in Apache HTTP Server, which can be exploited by malicious people to disclose potentially sensitive information and cause a DoS (Denial of Service).

  1. An error when handling the "%{cookiename}C" log format string when using a threaded MPM can be exploited to cause a crash by sending a specially crafted cookie.
  2. An error within the default error response for status code 400 when no custom ErrorDocument is configured can be exploited to expose "httpOnly" cookies.

Impact

  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • Apache 2.2.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link