CVE-2010-2791
EPSS 8.3%
描述
mod_proxy in httpd in Apache HTTP Server 2.2.9, when running on Unix, does not close the backend connection if a timeout occurs when reading a response from a persistent connection, which allows remote attackers to obtain a potentially sensitive response intended for a different client in opportunistic circumstances via a normal HTTP request. NOTE: this is the same issue as CVE-2010-2068, but for a different OS and set of affected versions.
如何修補 CVE-2010-2791
要修補 CVE-2010-2791,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.2.9-10 或更新版本
CVE-2010-2791 正在被利用嗎?
中等 — EPSS 為 8.3%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2.2.9-10