|
|
|
![]() |
Vulnerability Note VU#366020Apache mod_tcl module contains a format string errorOverviewA format string vulnerability exists in the mod_tcl Apache module. This vulnerability may allow a remote attacker to execute arbitrary code.I. DescriptionThe Apache HTTP Server, also known as httpd, is an open-source HTTP server that runs on Microsoft Windows, Linux, Unix, and Apple OS X Operating Systems. Apache modules can be used to extend the functionality of the Apache web server. The mod_tcl module is a scripting module that allows Apache to run TCL scripts natively.There is a format string vulnerability in the mod_tcl module that may allow an attacker to execute arbitrary code.
The mod_tcl team has released an upgrade that addresses this issue.
References
Thanks to the mod_tcl and Gentoo teams for providing information about this vulnerability. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||