Full Disclosure mailing list archives

Remotely exploitable b/o/f in Apache+mod_mylo


From: Carl Livitt <carl () learningshophull co uk>
Date: Mon, 28 Jul 2003 14:44:56 +0000


There exists a remotely exploitable buffer overflow in the mod_mylo module for 
apache. 

It is a relatively obscure MySQL logging module for Apache that appears not to 
be in widespread use at present. However, it is present in the FreeBSD ports 
collection so may affect FreeBSD slighly more than Linux systems.

Advisory + exploit attached.

Regards,
Carl

Attachment: CLIVITT-2003-5 (apache+mod_mylo).txt
Description:


Current thread: