239
Apache 2.0.47 to 2.0.49 ap_escape_html memory allocation denial of service
HTTP
2004/09/16
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/14
2.0
Corrected the plugin structure and added the accuracy values in 1.1. Added the product produce information in version 1.2. Improved the pattern matching and introduced the plugin changelog in 2.0
tcp
80
open|send HEAD / HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/1.[0-1] ### *Server: Apache/1.* OR HTTP/1.[0-1] ### *Server: Apache/2.0.[3-4][0-9]*
80
This vulnerability seems not to be very well documented. So perhaps Apache prior 2.0.47 are vulnerable too. Apache 1.x is not vulnerable for sure.
Georgi Guninski
guninski at guninski dot com
http://www.guninski.com
2004/06/28
http://www.securityfocus.com/advisories/6915
Apache Software Foundation
apache at apache dot org
http://httpd.apache.org
Apache 2.0.47 to 2.0.49
Apache prior 2.0.47 or newer than 2.0.49 or other web servers
Buffer Overflow
The remote host is running an Apache web server. Apache 2.0.47 to 2.0.49 is vulnerable to a buffer overflow in in excessively long HTTP header strings. It has been documented that only denial of service is possible. Running arbitrary code seems not to work.
If the web server is not used it should be de-installed or de-activated. Install the newest patch or bugfix to solve the problem or upgrade to the latest software version which is not vulnerable anymore.
Approx. 30 minutes
Yes
http://www.securityfocus.com/bid/10619/exploit/
Yes
Yes
Medium
4
5
8
5
BED by Martin J. Münch and SnakeByte seems to detect this vulnerability.
CAN-2004-0493
10619
RHSA-2004-342
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.securityfocus.com/advisories/6907