Title: Apache mod_php Module File Descriptor Leakage Vulnerability
Severity: MODERATE
Description:
Apache is a freely available, open-source webserver software package. It is distributed and maintained by the Apache Group. The mod_php module allows for PHP functionality in websites.
A vulnerability has been reported to reside in the Apache mod_php module. The issue may allow local attackers to gain access to privileged file descriptors and then hijack a vulnerable server daemon.
Reportedly, the file descriptor associated with the socket listening on port 443, normally used for Secure Sockets Layer (SSL), is leaked to the mod_php module and any processes it creates. This allows for scripts and any processes they spawn to access the privileged port.
Exploiting this issue may allow an attacker to pose as a legitimate server to clients. An attacker may also steal sensitive information such as user credentials and other authentication information.
Affected Products:
- Apache Software Foundation Apache 2.0.0
- Apache Software Foundation Apache 2.0.0 a9
- Apache Software Foundation Apache 2.0.28
- Apache Software Foundation Apache 2.0.28 Beta
- Apache Software Foundation Apache 2.0.32
- Apache Software Foundation Apache 2.0.35
- Apache Software Foundation Apache 2.0.36
- Apache Software Foundation Apache 2.0.37
- Apache Software Foundation Apache 2.0.38
- Apache Software Foundation Apache 2.0.39
- Apache Software Foundation Apache 2.0.40
- Apache Software Foundation Apache 2.0.41
- Apache Software Foundation Apache 2.0.42
- Apache Software Foundation Apache 2.0.43
- Apache Software Foundation Apache 2.0.44
- Apache Software Foundation Apache 2.0.45
- Apache Software Foundation Apache 2.0.46
- Apache Software Foundation Apache 2.0.47
- Apache Software Foundation Apache 2.0.48
- Apache Software Foundation Apache for Windows 2.0.28 -BETA
- Apache Software Foundation Apache for Windows 2.0.32 -BETA
- Apache Software Foundation Apache for Windows 2.0.34 -BETA
- Apache Software Foundation Apache for Windows 2.0.46
- Apple Mac OS X Server 10.1.0
- Apple Mac OS X Server 10.1.1
- Apple Mac OS X Server 10.1.2
- Apple Mac OS X Server 10.1.3
- Apple Mac OS X Server 10.1.4
- Apple Mac OS X Server 10.1.5
- Apple Mac OS X Server 10.2.0
- Apple Mac OS X Server 10.2.1
- Apple Mac OS X Server 10.2.2
- Apple Mac OS X Server 10.2.3
- Apple Mac OS X Server 10.2.4
- Apple Mac OS X Server 10.2.5
- Apple Mac OS X Server 10.2.6
- Apple Mac OS X Server 10.2.7
- Apple Mac OS X Server 10.2.8
- Apple Mac OS X Server 10.3.0
- Apple Mac OS X Server 10.3.1
- Apple Mac OS X Server 10.3.2
- Apple Mac OS X Server 10.3.3
- Apple Mac OS X Server 10.3.4
- Apple Mac OS X Server 10.3.5
- Conectiva Linux 9.0.0
- Gentoo Linux 1.2.0
- Gentoo Linux 1.4.0 _rc1
- IBM HTTP Server 2.0.42
- IBM HTTP Server 2.0.42 .1
- IBM HTTP Server 2.0.42 .2
- MandrakeSoft Linux Mandrake 10.0.0
- MandrakeSoft Linux Mandrake 10.0.0 amd64
- MandrakeSoft Linux Mandrake 9.1.0
- MandrakeSoft Linux Mandrake 9.1.0 ppc
- MandrakeSoft Linux Mandrake 9.2.0
- MandrakeSoft Linux Mandrake 9.2.0 amd64
- RedHat Desktop 3.0.0
- RedHat Enterprise Linux AS 3
- RedHat Enterprise Linux ES 3
- RedHat Enterprise Linux WS 3
- RedHat Linux 8.0.0
- RedHat Linux 9.0.0 i386
- S.u.S.E. Linux 8.1.0
- S.u.S.E. Linux Personal 8.2.0
- S.u.S.E. Linux Personal 9.0.0
- S.u.S.E. Linux Personal 9.0.0 x86_64
- Terra Soft Solutions Yellow Dog Linux 3.0.0
- Trustix Secure Linux 2.0.0
- Trustix Secure Linux 2.1.0
- Yellow Dog Linux Yellow Dog Linux 3.0.0
References:
- Apache Software Foundation: Apache Homepage
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.