239 Apache 2.0.47 to 2.0.49 ap_escape_html memory allocation denial of service HTTP 2004/09/16 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/14 2.0 Corrected the plugin structure and added the accuracy values in 1.1. Added the product produce information in version 1.2. Improved the pattern matching and introduced the plugin changelog in 2.0 tcp 80 open|send HEAD / HTTP/1.0\n\n|sleep|close|pattern_exists HTTP/1.[0-1] ### *Server: Apache/1.* OR HTTP/1.[0-1] ### *Server: Apache/2.0.[3-4][0-9]* 80 This vulnerability seems not to be very well documented. So perhaps Apache prior 2.0.47 are vulnerable too. Apache 1.x is not vulnerable for sure. Georgi Guninski guninski at guninski dot com http://www.guninski.com 2004/06/28 http://www.securityfocus.com/advisories/6915 Apache Software Foundation apache at apache dot org http://httpd.apache.org Apache 2.0.47 to 2.0.49 Apache prior 2.0.47 or newer than 2.0.49 or other web servers Buffer Overflow The remote host is running an Apache web server. Apache 2.0.47 to 2.0.49 is vulnerable to a buffer overflow in in excessively long HTTP header strings. It has been documented that only denial of service is possible. Running arbitrary code seems not to work. If the web server is not used it should be de-installed or de-activated. Install the newest patch or bugfix to solve the problem or upgrade to the latest software version which is not vulnerable anymore. Approx. 30 minutes Yes http://www.securityfocus.com/bid/10619/exploit/ Yes Yes Medium 4 5 8 5 BED by Martin J. Münch and SnakeByte seems to detect this vulnerability. CAN-2004-0493 10619 RHSA-2004-342 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.securityfocus.com/advisories/6907