Article 4CEAH Serious Apache server bug gives root to baddies in shared host environments

Serious Apache server bug gives root to baddies in shared host environments

by
Dan Goodin
from Ars Technica - All content on (#4CEAH)
apache-match.jpg

(credit: Aurich Lawson / Thinkstock)

The Apache HTTP Server, the Internet's most widely used Web server, just fixed a serious vulnerability that makes it possible for untrusted users or software to gain unfettered control of the machine the software runs on.

CVE-2019-0211, as the vulnerability is indexed, is a local privilege escalation, meaning it allows a person or software that already has limited access to the Web server to elevate privileges to root. From there, the attacker could do just about anything. The vulnerability makes it possible for unprivileged scripts to overwrite sensitive parts of a server's memory, Charles Fol, the independent researcher who discovered the bug, wrote in a blog post. A malicious script could exploit the vulnerability to gain root.

The vulnerability poses the most risk inside Web-hosting facilities that offer shared instances, in which a single physical machine serves content for more than one website. Typically, such servers prevent an administrator of one site from accessing other sites or from accessing sensitive settings of the machine itself.

Read 5 remaining paragraphs | Comments

index?i=c6q3aAi6_o4:J52Oe_53xE0:V_sGLiPB index?i=c6q3aAi6_o4:J52Oe_53xE0:F7zBnMyn index?d=qj6IDK7rITs index?d=yIl2AUoC8zA
External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments