CVE-2010-0425
Summary
| CVE | CVE-2010-0425 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-05 19:30:00 UTC |
| Updated | 2023-11-07 02:05:00 UTC |
| Description | modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers." |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | - | All | All | All |
| Application | Apache | Http Server | 2.0.28 | All | All | All |
| Application | Apache | Http Server | 2.0.28 | beta | All | All |
| Application | Apache | Http Server | 2.0.32 | All | All | All |
| Application | Apache | Http Server | 2.0.32 | beta | All | All |
| Application | Apache | Http Server | 2.0.34 | beta | All | All |
| Application | Apache | Http Server | 2.0.35 | All | All | All |
| Application | Apache | Http Server | 2.0.36 | All | All | All |
| Application | Apache | Http Server | 2.0.37 | All | All | All |
| Application | Apache | Http Server | 2.0.38 | All | All | All |
| Application | Apache | Http Server | 2.0.39 | All | All | All |
| Application | Apache | Http Server | 2.0.40 | All | All | All |
| Application | Apache | Http Server | 2.0.41 | All | All | All |
| Application | Apache | Http Server | 2.0.42 | All | All | All |
| Application | Apache | Http Server | 2.0.43 | All | All | All |
| Application | Apache | Http Server | 2.0.44 | All | All | All |
| Application | Apache | Http Server | 2.0.45 | All | All | All |
| Application | Apache | Http Server | 2.0.46 | All | All | All |
| Application | Apache | Http Server | 2.0.47 | All | All | All |
| Application | Apache | Http Server | 2.0.48 | All | All | All |
| Application | Apache | Http Server | 2.0.49 | All | All | All |
| Application | Apache | Http Server | 2.0.50 | All | All | All |
| Application | Apache | Http Server | 2.0.51 | All | All | All |
| Application | Apache | Http Server | 2.0.52 | All | All | All |
| Application | Apache | Http Server | 2.0.53 | All | All | All |
| Application | Apache | Http Server | 2.0.54 | All | All | All |
| Application | Apache | Http Server | 2.0.55 | All | All | All |
| Application | Apache | Http Server | 2.0.56 | All | All | All |
| Application | Apache | Http Server | 2.0.57 | All | All | All |
| Application | Apache | Http Server | 2.0.58 | All | All | All |
| Application | Apache | Http Server | 2.0.59 | All | All | All |
| Application | Apache | Http Server | 2.0.60 | All | All | All |
| Application | Apache | Http Server | 2.0.61 | All | All | All |
| Application | Apache | Http Server | 2.0.63 | All | All | All |
| Application | Apache | Http Server | 2.0.9 | All | All | All |
| Application | Apache | Http Server | 2.2.0 | All | All | All |
| Application | Apache | Http Server | 2.2.1 | All | All | All |
| Application | Apache | Http Server | 2.2.10 | All | All | All |
| Application | Apache | Http Server | 2.2.11 | All | All | All |
| Application | Apache | Http Server | 2.2.12 | All | All | All |
| Application | Apache | Http Server | 2.2.13 | All | All | All |
| Application | Apache | Http Server | 2.2.14 | All | All | All |
| Application | Apache | Http Server | 2.2.2 | All | All | All |
| Application | Apache | Http Server | 2.2.3 | All | All | All |
| Application | Apache | Http Server | 2.2.4 | All | All | All |
| Application | Apache | Http Server | 2.2.6 | All | All | All |
| Application | Apache | Http Server | 2.2.7 | All | All | All |
| Application | Apache | Http Server | 2.2.8 | All | All | All |
| Application | Apache | Http Server | 2.2.9 | All | All | All |
| Application | Apache | Http Server | 2.3.0 | All | All | All |
| Application | Apache | Http Server | 2.3.1 | All | All | All |
| Application | Apache | Http Server | 2.3.2 | All | All | All |
| Application | Apache | Http Server | 2.3.3 | All | All | All |
| Application | Apache | Http Server | 2.3.4 | All | All | All |
| Application | Apache | Http Server | 2.3.5 | All | All | All |
| Application | Apache | Http Server | 2.3.6 | All | All | All |
| Application | Apache | Http Server | - | All | All | All |
| Application | Apache | Http Server | 2.0.28 | All | All | All |
| Application | Apache | Http Server | 2.0.28 | beta | All | All |
| Application | Apache | Http Server | 2.0.32 | All | All | All |
| Application | Apache | Http Server | 2.0.32 | beta | All | All |
| Application | Apache | Http Server | 2.0.34 | beta | All | All |
| Application | Apache | Http Server | 2.0.35 | All | All | All |
| Application | Apache | Http Server | 2.0.36 | All | All | All |
| Application | Apache | Http Server | 2.0.37 | All | All | All |
| Application | Apache | Http Server | 2.0.38 | All | All | All |
| Application | Apache | Http Server | 2.0.39 | All | All | All |
| Application | Apache | Http Server | 2.0.40 | All | All | All |
| Application | Apache | Http Server | 2.0.41 | All | All | All |
| Application | Apache | Http Server | 2.0.42 | All | All | All |
| Application | Apache | Http Server | 2.0.43 | All | All | All |
| Application | Apache | Http Server | 2.0.44 | All | All | All |
| Application | Apache | Http Server | 2.0.45 | All | All | All |
| Application | Apache | Http Server | 2.0.46 | All | All | All |
| Application | Apache | Http Server | 2.0.47 | All | All | All |
| Application | Apache | Http Server | 2.0.48 | All | All | All |
| Application | Apache | Http Server | 2.0.49 | All | All | All |
| Application | Apache | Http Server | 2.0.50 | All | All | All |
| Application | Apache | Http Server | 2.0.51 | All | All | All |
| Application | Apache | Http Server | 2.0.52 | All | All | All |
| Application | Apache | Http Server | 2.0.53 | All | All | All |
| Application | Apache | Http Server | 2.0.54 | All | All | All |
| Application | Apache | Http Server | 2.0.55 | All | All | All |
| Application | Apache | Http Server | 2.0.56 | All | All | All |
| Application | Apache | Http Server | 2.0.57 | All | All | All |
| Application | Apache | Http Server | 2.0.58 | All | All | All |
| Application | Apache | Http Server | 2.0.59 | All | All | All |
| Application | Apache | Http Server | 2.0.60 | All | All | All |
| Application | Apache | Http Server | 2.0.61 | All | All | All |
| Application | Apache | Http Server | 2.0.63 | All | All | All |
| Application | Apache | Http Server | 2.0.9 | All | All | All |
| Application | Apache | Http Server | 2.2.0 | All | All | All |
| Application | Apache | Http Server | 2.2.1 | All | All | All |
| Application | Apache | Http Server | 2.2.10 | All | All | All |
| Application | Apache | Http Server | 2.2.11 | All | All | All |
| Application | Apache | Http Server | 2.2.12 | All | All | All |
| Application | Apache | Http Server | 2.2.13 | All | All | All |
| Application | Apache | Http Server | 2.2.14 | All | All | All |
| Application | Apache | Http Server | 2.2.2 | All | All | All |
| Application | Apache | Http Server | 2.2.3 | All | All | All |
| Application | Apache | Http Server | 2.2.4 | All | All | All |
| Application | Apache | Http Server | 2.2.6 | All | All | All |
| Application | Apache | Http Server | 2.2.7 | All | All | All |
| Application | Apache | Http Server | 2.2.8 | All | All | All |
| Application | Apache | Http Server | 2.2.9 | All | All | All |
| Application | Apache | Http Server | 2.3.0 | All | All | All |
| Application | Apache | Http Server | 2.3.1 | All | All | All |
| Application | Apache | Http Server | 2.3.2 | All | All | All |
| Application | Apache | Http Server | 2.3.3 | All | All | All |
| Application | Apache | Http Server | 2.3.4 | All | All | All |
| Application | Apache | Http Server | 2.3.5 | All | All | All |
| Application | Apache | Http Server | 2.3.6 | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Apache 2.2.14 mod_isapi Dangling Pointer Remote SYSTEM Exploit | MISC | www.exploit-db.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Oracle Critical Patch Update - July 2013 | CONFIRM | www.oracle.com | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Apache 'mod_isapi' Memory Corruption Vulnerability | BID | www.securityfocus.com | Exploit |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| IBM HTTP Server mod_isapi Module Unloading Vulnerability - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| IBM PM09447: CVE-2010-0425 MOD_ISAPI VULNERABILITY - United States | AIXAPAR | www-01.ibm.com | |
| US-CERT Vulnerability Note VU#280613 | CERT-VN | www.kb.cert.org | US Government Resource |
| Pony Mail! | MLIST | lists.apache.org | |
| Sense of Security - Security Advisory - SOS-10-002 - Apache 2.2.14 mod_isapi Dangling Pointer Vulnerability | MISC | www.senseofsecurity.com.au | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| SecurityTracker.com Archives - Apache mod_isapi Error Processing Flaw May Let Remote Users Deny Service | SECTRACK | www.securitytracker.com | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| [Apache-SVN] Diff of /httpd/httpd/trunk/CHANGES | CONFIRM | svn.apache.org | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| httpd 2.2 vulnerabilities - The Apache HTTP Server Project | CONFIRM | httpd.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| IBM PM12247: SHIP APAR FIXES FOR H28W610 FIX PACK 6.1.0.31. - United States | AIXAPAR | www-01.ibm.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| VMSA-2010-0014 | CONFIRM | www.vmware.com | |
| [Apache-SVN] Diff of /httpd/httpd/trunk/modules/arch/win32/mod_isapi.c | CONFIRM | svn.apache.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| IBM WebSphere Application Server for z/OS Multiple Vulnerabilities - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| [Apache-SVN] Revision 917870 | CONFIRM | svn.apache.org | |
| Apache httpd 2.0 vulnerabilities - The Apache HTTP Server Project | CONFIRM | httpd.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| [Security-announce] VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues | MLIST | lists.vmware.com | |
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.