FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-4001

This CVE name corresponds to:

Entered Topic
2012-09-12 mod_pagespeed -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-4001
Phase Assigned(20120712)

Description

The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.

References

Source Reference
CONFIRM https://developers.google.com/speed/docs/mod_pagespeed/CVE-2012-4001
CONFIRM https://developers.google.com/speed/docs/mod_pagespeed/announce-0.10.22.6