---
title: "CVE-2010-0425\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2010-0425?format=md
keywords: index, follow
---

# CVE-2010-0425

Publication date 5 March 2010

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

modules/arch/win32/mod\_isapi.c in mod\_isapi in the Apache HTTP Server
2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when
running on Windows, does not ensure that request processing is complete
before calling isapi\_unload for an ISAPI .dll module, which allows remote
attackers to execute arbitrary code via unspecified vectors related to a
crafted request, a reset packet, and "orphaned callback pointers."

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| apache2 | 9.10 karmic | Not affected |
| 9.04 jaunty | Not affected |
| 8.10 intrepid | Not affected |
| 8.04 LTS hardy | Not affected |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0425)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2010-0425)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2010-0425)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2010-0425)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2010-0425>
