CVE-2009-1191
Priority
Low
Description
mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server
2.2.11 allows remote attackers to obtain sensitive response data, intended
for a client that sent an earlier POST request with no request body, via an
HTTP request.
References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1191
http://www.ubuntu.com/usn/usn-787-1
Notes
jdstrand> affected code only in 2.2.11 (Ubuntu 9.04)
Assigned-to
jdstrand
Package
Source:
apache2
(
LP
Ubuntu
Debian
)
Upstream:
released
(2.2.11-4)
Ubuntu 8.04 LTS (Hardy Heron)
:
not-affected
More Information
Mitre
NVD
Launchpad
Debian
Updated
: 2012-06-01 15:19:45 UTC (commit
5347
)