OSVDB ID: 29536

Title: Apache Tcl mod_tcl set_var Function Remote Format String

Info

Disclosure

Oct 13, 2006

Discovery

Aug 16, 2006

Dates

Exploit

Unknown

Solution

Unknown

Description

A remote format string vulnerability exists in mod_tcl for the Apache HTTP server. There are format string errors in tcl_cmds.c and tcl_core.c when calling the "set_var()" with user supplied input. With a specially crafted request, an attacker can cause the execution of arbitrary code.

Classification

Location: Remote / Network Access, Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Private, Exploit Unknown
Disclosure: OSVDB Verified

Solution

Upgrade to version 1.0.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Apache Software Foundation

mod_tcl

1.0

References

Credit

  • Sparfell -


Direct URL: http://osvdb.org/29536