imPC@ndo IT

Tracker / CVE-2019-0211

CVE-2019-0211

Exploited High 7.8

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

Affected products and versions

apache http_server · 2.4.17 → 2.4.38
canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
netapp oncommand_unified_manager
opensuse leap
oracle communications_session_report_manager
oracle communications_session_route_manager
oracle enterprise_manager_ops_center
oracle http_server
oracle instantis_enterprisetrack
oracle retail_xstore_point_of_service
redhat enterprise_linux
redhat enterprise_linux_eus
redhat enterprise_linux_for_arm_64
redhat enterprise_linux_for_arm_64_eus
redhat enterprise_linux_for_ibm_z_systems
redhat enterprise_linux_for_ibm_z_systems_eus
redhat enterprise_linux_for_power_little_endian
redhat enterprise_linux_for_power_little_endian_eus
redhat enterprise_linux_server_aus
redhat enterprise_linux_server_tus
redhat enterprise_linux_update_services_for_sap_solutions
redhat jboss_core_services
redhat openshift_container_platform
redhat openshift_container_platform_for_power
redhat software_collections

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References