The target is running an Apache web server which allows for the injection of arbitrary escape sequences into its error logs. An attacker might use this vulnerability in an attempt to exploit similar vulnerabilities in terminal emulators. ***** OVS has determined the vulnerability exists only by looking at ***** the Server header returned by the web server running on the target.
Upgrade to Apache version 1.3.31 or 2.0.49 or newer.
- Adobe Reader Information Disclosure & Denial of Service Vulnerabilities (Windows)
- Adobe Digital Edition Information Disclosure Vulnerability (Windows)
- Apple Safari Multiple Vulnerabilities Dec13 (Mac OS X)
- Aardvark Topsites Multiple Vulnerabilities
- Adobe Reader Cross-Site Scripting & Denial of Service Vulnerabilities (Mac OS X)