Re: CVE-2021-42013: Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

Related Vulnerabilities: CVE-2021-42013   CVE-2021-41773  
                Hi Yann,

Re [1], I think this:

"critical: Path traversal and file disclosure vulnerability in Apache
HTTP Server 2.4.49 (CVE-2021-41773
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41773>)"

is still misleading and should read:

"critical: Path traversal and *Remote Code Execution* vulnerability in
Apache HTTP Server 2.4.49 (CVE-2021-41773
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41773>)"

PS: Dear Alexander, feel free to drop this from OSS-ml if you think this
kind of detail is not relevant.

Cheers,

-r

El 11/10/2021 a las 10:57, Yann Ylavic escribió:

-- 
Saludos,
-Román