Back

MEDIUM

mod_auth_shadow: bad wait(2) call causes randomized authorization behaviour

Published Apr 20, 2010

Description

Race condition in the mod_auth_shadow module for the Apache HTTP Server allows remote attackers to bypass authentication, and read and possibly modify data, via vectors related to improper interaction with an external helper application for validation of credentials.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 20, 2010
Updated Aug 7, 2024
Reserved Mar 29, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Apr 9, 2010