Description
By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory. However function pointers still remain in memory and are called when published ISAPI functions are referenced. This results in a dangling pointer vulnerability.
Affected Apache versions (up to 2.2.14 on Windows platform).
Remediation
Upgrade Apache to the latest version.
References
Related Vulnerabilities
MySQL CVE-2020-14568 Vulnerability (CVE-2020-14568)
YetiForce CRM Improper Input Validation Vulnerability (CVE-2021-4111)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-9775)
Joomla! Core Arbitrary File Upload (2.5.0 - 3.8.7)
Oracle Database Server CVE-2010-0901 Vulnerability (CVE-2010-0901)