Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 398761 (CVE-2012-0031)

Summary: <www-servers/apache-2.2.22 Scoreboard Invalid Free Security Bypass (CVE-2012-0031)
Product: Gentoo Security Reporter: Agostino Sarubbo <ago>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: apache-bugs, pva
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://secunia.com/advisories/47410/
Whiteboard: B4 [glsa]
Package list:
Runtime testing required: ---
Bug Depends on: 401761    
Bug Blocks:    

Description Agostino Sarubbo gentoo-dev 2012-01-13 12:21:16 UTC
From secunia security advisory at $URL:

Description:
The weakness is caused due to child processes being able to change the memory type record of the "scoreboard" shared memory segment, which can be exploited to cause an invalid free operation during the shutdown of the parent process.


Solution:
Fixed in the SVN repository.
http://svn.apache.org/viewvc?view=revision&revision=1230065
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2012-04-18 00:03:35 UTC
Added to existing GLSA request.
Comment 2 Tobias Heinlein (RETIRED) gentoo-dev 2012-06-21 20:27:45 UTC
For the record: CVE in bug 401081.
Comment 3 GLSAMaker/CVETool Bot gentoo-dev 2012-06-24 14:29:26 UTC
This issue was resolved and addressed in
 GLSA 201206-25 at http://security.gentoo.org/glsa/glsa-201206-25.xml
by GLSA coordinator Tobias Heinlein (keytoaster).