|
|
|
![]() |
Vulnerability Note VU#125235Apache Web Server vulnerable to DoS via crafted HTTP requestOverviewSome versions of the Apache Web server are vulnerable to denial-of-service attacks by crafted HTTP requests.I. DescriptionA vulnerability exists in some versions the Apache Web (HTTPD) Server running on Windows 98SE, Windows 2000 SP1, and OS/2. The vulnerability appears to be a bounds checking problem in HTTP requests. Receipt of an HTTP request 8192 characters in length can exploit the vulnerability.II. ImpactAn attacker could cause the server to crash.III. SolutionUpgrade to version Apache HTTPD Server 1.3.20 or later. For more info, see:http://bugs.apache.org/index.cgi/full/7522
References
Thanks to Auriemma Luigi and Security Tracker for reporting this vulnerability. This document was written by Shawn Van Ittersum.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||