SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#481998

Apache vulnerable to buffer overflow when expanding environment variables

Overview

There is a buffer overflow vulnerability in ap_resolve_env() function of Apache that could allow a local user to gain elevated privileges.

I. Description

The Apache HTTP Server is a freely available web server that runs on a variety of operating systems including Unix, Linux, and Microsoft Windows. The ap_resolve_env() function is responsible for expanding environment variables when parsing configurations files such as .htaccess or httpd.conf. There is a vulnerability in this function that could allow a local user to trigger a buffer overflow.

The Apache Software Foundation notes that in order to exploit this vulnerability, a local user would need to install the malicious configuration file on the server and force the server to parse this file.

II. Impact

A local user with the ability to force a vulnerable to server to parse a malicious configuration file could gain elevated privileges.

III. Solution

Upgrade or Apply Patch

Upgrade or apply patch as specified by your vendor. This issue is resolved in Apache version 2.0.51.

Systems Affected

VendorStatusDate NotifiedDate Updated
ApacheVulnerable17-Sep-2004

References


http://www.apache.org/dist/httpd/Announcement2.html
http://www.uniras.gov.uk/vuls/2004/403518/index.htm
http://secunia.com/advisories/12540/
http://www.securitytracker.com/alerts/2004/Sep/1011303.html
http://rhn.redhat.com/errata/RHSA-2004-463.html

Credit

This vulnerability was reported by the Swedish IT Incident Centre within the National Post and Telecom Agency (SITIC).

This document was written by Damon Morda.

Other Information

Date Public:2004-09-15
Date First Published:2004-09-17
Date Last Updated:2004-09-17
CERT Advisory: 
CVE-ID(s):CAN-2004-0747
NVD-ID(s):CAN-2004-0747
US-CERT Technical Alerts: 
Metric:3.37
Document Revision:9

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader