CVE-2012-3502

Publication date 22 August 2012

Last updated 24 July 2024


Ubuntu priority

The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive information in opportunistic circumstances by reading a response that was intended for a different client.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
apache2 12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected

Notes


sbeattie

2.4.x only