mailing list archives
Apache scoreboard invalid free on shutdown in master process
From: halfdog <me () halfdog net>
Date: Thu, 12 Jan 2012 11:33:32 +0000
-----BEGIN PGP SIGNED MESSAGE-----
Modification of apache scoreboard data, shared by root (uid=0) and
www-data process, allows triggering of invalid free in root process
during apache shutdown, exploitation seems impossible except for really
broken chroot configs.
The free is triggered by setting the scoreboard type from
shared-mem-type to malloc-type. This is possible because the
scoreboard type setting is also stored in shared memory and hence
changeable by lower-privileged worker process.
PGP: 156A AE98 B91F 0114 FE88 2BD8 C459 9386 feed a bee
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
-----END PGP SIGNATURE-----
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
- Apache scoreboard invalid free on shutdown in master process halfdog (Jan 12)