|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
FastCGI mod_fastcgi contains a flaw that may allow an attacker to corrupt the error log. The issue is due to the fopen for append procedure not properly handling two processes attempting to append to the same file. This causes the process manager to corrupt the error log resulting in a loss of integrity and availability.
|
|
Classification |
Location:
Local Access Required,
Remote/Network Access Required
Attack Type:
Denial of Service
Impact:
Loss of Integrity,
Loss of Availability
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Upgrade to version 1.3.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
mod_fastcgi
 |
1.3 |
1.3.1 |
|
|
|
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|