[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2014-0242
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.

CVE-2014-0240
The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes.

*OVAL
oval:org.secpod.oval:def:1500598
CPE    23
cpe:/a:modwsgi:mod_wsgi:1.2
cpe:/a:modwsgi:mod_wsgi:2.1
cpe:/a:modwsgi:mod_wsgi:3.0
cpe:/a:modwsgi:mod_wsgi:1.3
...

© SecPod Technologies