Oval Definition:oval:com.ubuntu.precise:def:20148109000
Revision Date:2014-12-29Version:1
Title:CVE-2014-8109 on Ubuntu 12.04 LTS (precise) - low.
Description:mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multiple Require directives, as demonstrated by a configuration that specifies authorization for one group to access a certain directory, and authorization for a second group to access a second directory.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-8109
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND While related to the CVE in some way, the 'apache2' package in precise is not affected (note: '2.2.22-1ubuntu1.7').
  • BACK