Sun Solaris mod_perl Two Vulnerabilities
SECUNIA ADVISORY ID: SA37303
VERIFY ADVISORY: http://secunia.com/advisories/37303/
DESCRIPTION: Sun has acknowledged two vulnerabilities in Solaris, which can be exploited by malicious people to conduct cross-site scripting attacks or potentially cause a DoS (Denial of Service).
For more information: SA24678 SA34597
The vulnerabilities are reported in Solaris 10 for both the SPARC and x86 platforms, running the Apache 2 web server.
SOLUTION: Do not configure the PerlRun.pm and Status.pm mod_perl2(3) components in httpd.conf. See the vendor’s advisory for more information.
A final resolution is pending completion for Solaris 10.
ORIGINAL ADVISORY: http://sunsolve.sun.com/search/document.do?assetkey=1-66-272230-1
OTHER REFERENCES: SA24678: http://secunia.com/advisories/24678/
SA34597: http://secunia.com/advisories/34597/
———————————————————————-
