SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#541310

Apache HTTP Server contains a buffer overflow in the mod_proxy module

Overview

Apache Web Server contains a buffer overflow vulnerability in the mod_proxy module that may allow a remote attacker to execute arbitrary code or launch a denial of service (DoS) attack.

I. Description

The Apache Server is an open-source web server offered by The Apache Software Foundation. The Apache Server uses the mod_proxy module to implement proxying for various common protocols such as FTP and HTTP. In versions of Apache prior to and including 1.3.31-r2, the mod_proxy module contains a buffer overflow vulnerability located in the file proxy_util.c. To exploit this vulnerability an attacker must persuade an Apache server with mod_proxy enabled to connect to a malicious server configured to return an invalid content-length header.

II. Impact

A remote attacker may be able to execute arbitrary code with the privileges of an Apache child process. Exploitation of this vulnerability may completely disable the Apache

server resulting in a denial-of-service condition.

III. Solution

Upgrade Apache


Apache states this issue was fixed in Apache httpd 1.3.32-dev.

Systems Affected

VendorStatusDate NotifiedDate Updated
ApacheVulnerable20-Aug-2004

References


http://www.guninski.com/modproxy1.html
http://secunia.com/advisories/11841/
http://www-1.ibm.com/support/docview.wss?rs=177&context=SSEQTJ&uid=swg21173021

Credit

This vulnerability was reported by Georgi Guninski.

This document was written by Jeff Gennari.

Other Information

Date Public:2004-06-10
Date First Published:2004-10-19
Date Last Updated:2004-10-19
CERT Advisory: 
CVE-ID(s):CAN-2004-0492
NVD-ID(s):CAN-2004-0492
US-CERT Technical Alerts: 
Metric:4.02
Document Revision:106

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader