New Apache flaw adds to Internet woes

ZDNet | at | by Mike

The Apache flaw could allow an attacker to discover sensitive information or execute malicious code, while the Windows bug makes it possible for users to gain privileges high enough to alter files and user accounts. The Apache flaw affects versions 2.0.39 and earlier, but only affects non-Unix platforms such as Windows, OS2 and Netware. The software can be made to reveal the absolute path to a script whenever the server attempts, and fails, to execute the script. Such path information would give valuable information to a potential attacker. An attacker could also use the flaw to execute programs on the server.

The new Apache flaw comes shortly after researchers publicized several security holes in OpenSSL, a security protocol, which could open the door to attacks on Apache servers. These flaws, along with other recent vulnerabilities in Apache and Microsoft servers, led one Internet researcher to comment on Tuesday that "a great many e-commerce sites are presently vulnerable to direct attack over the Internet."