Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
BID:73040
Info
Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
| Bugtraq ID: | 73040 |
| Class: | Design Error |
| CVE: |
CVE-2014-8109 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 09 2014 12:00AM |
| Updated: | Feb 11 2016 07:36AM |
| Credit: | Edward Lu |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Slackware Slackware Linux 13.37 Slackware Slackware Linux 13.0 Oracle Enterprise Manager Ops Center 11.1 Apache Software Foundation Apache 2.4.2 |
| Not Vulnerable: | |
Discussion
Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
Apache HTTP Server is prone to a local access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Apache HTTP Server is prone to a local access-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions.
Exploit / POC
Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache HTTP Server 'mod_lua.c' Local Access Bypass Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)