#VU22945 Code Injection in mod_perl


Published: 2019-11-24

Vulnerability identifier: #VU22945

Vulnerability risk: Medium

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2011-2767

CWE-ID: CWE-94

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
mod_perl
Universal components / Libraries / Scripting languages

Vendor: Apache Foundation

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to absence of functionality that can be used to disable execution of Perl code if placed into .htaccess file. A remote attacker with access to the web server can modify Apache .htaccess file, insert Perl code into it and execute the code on the server with privileges of Apache HTTP server.

Successful exploitation of this vulnerability requires that mod_perl is installed and that the attacker is able to modify .htaccess files.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

mod_perl: 2.0.0 - 2.0.10


External links
http://access.redhat.com/errata/RHSA-2018:2737
http://access.redhat.com/errata/RHSA-2018:2825
http://access.redhat.com/errata/RHSA-2018:2826
http://bugs.debian.org/644169
http://lists.apache.org/thread.html/c8ebe8aad147a3ad2e7b0e8b2da45263171ab5d0fc7f8c100feaa94d@%3Cmodperl-cvs.perl.apache.org%3E
http://lists.debian.org/debian-lts-announce/2018/09/msg00018.html
http://mail-archives.apache.org/mod_mbox/perl-modperl/201110.mbox/raw/%3C20111004084343.GA21290%40ktnx.net%3E


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability