Flaw of newest Apache server Gao Wei can carry authority to operate directly

Flaw of newest Apache server Gao Wei can carry authority to operate directly

Introduce according to official website, the version that this flaw place affects is very extensive, involve arrive from 2.4.17(2015.10.9) all version of 2.4.38(2019.4.1) .

The flaw that number is CVE-2019-0211 is a this locality carries authority flaw, the user that this flaw allows to have limited limits of authority or software win the Root limits of authority of Web Server. If be succeeded to carry power by aggressor, he will have the complete visit limits of authority of Web Server, be like,out is entered in the server.

Suffer this flaw to affect the biggest is to provide the Web mandatory business that shares example. Because Web is mandatory,a server of business can offer many websites to use normally, and the administrator that this kind of server can prevent a website commonly visits another website, or the sensitive setting that visits a machine.

Charles Fol expresses to cross paragraph of time to be able to announce the flaw about CVE-2019-0211 to use case.

Apache HTTP server released newest stable version 2.4.39, basically be repair the safe problem of flaw of this tall danger, update in time please

未经允许不得转载:News » Flaw of newest Apache server Gao Wei can carry authority to operate directly