SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#944335

Apache web servers fail to handle chunks with a negative size

Overview

There is a remotely exploitable vulnerability in the way that Apache web servers (or other web servers based on their source code) handle data encoded in chunks. This vulnerability is present by default in configurations of Apache web server versions 1.2.2 and above, 1.3 through 1.3.24, and versions 2.0 through 2.0.36. The impact of this vulnerability is dependent upon the software version and the hardware platform the server is running on.

I. Description

Apache is a popular web server that includes support for chunk-encoded data according to the HTTP 1.1 standard as described in RFC2616. There is a vulnerability in the handling of certain chunk-encoded HTTP requests that may allow remote attackers to execute arbitrary code.

The Apache Software Foundation has published an advisory describing the details of this vulnerability. This advisory is available on their web site at

II. Impact

For Apache versions 1.2.2 through 1.3.24 inclusive, this vulnerability may allow the execution of arbitrary code by remote attackers. Exploits are publicly available that claim to allow the execution of arbitrary code.


For Apache versions 2.0 through 2.0.36 inclusive, the condition causing the vulnerability is correctly detected and causes the child process to exit. Depending on a variety of factors, including the threading model supported by the vulnerable system, this may lead to a denial-of-service attack against the Apache web server.

III. Solution

Upgrade to the latest version


The Apache Software Foundation has released two new versions of Apache that correct this vulnerability. System administrators can prevent the vulnerability from being exploited by upgrading to Apache version 1.3.26 or 2.0.39.

Due to some unexpected problems with version 1.3.25, the CERT/CC has been informed by the Apache Software Foundation that the corrected version of the software is now 1.3.26. Both 1.3.26 and 2.0.39 are available on their web site at


Apply a patch from your vendor

If your vendor has provided a patch to correct this vulnerability, you may want to apply that patch rather than upgrading your version of httpd. The CERT/CC is aware of a patch from ISS that corrects some of the impacts associated with this vulnerability. System administrators are encouraged to ensure that the patch they apply is based on the code by the Apache Software Foundation that also corrects additional impacts described in this advisory.

More information about vendor-specific patches can be found in the vendor section of this document.

Systems Affected

VendorStatusDate Updated
3ComUnknown17-Jun-2002
AlcatelVulnerable28-Jun-2002
ApacheVulnerable17-Jun-2002
Apple Computer, Inc.Vulnerable2-Jul-2002
AT&TUnknown17-Jun-2002
Berkeley Software Design, Inc.Unknown17-Jun-2002
Cisco Systems, Inc.Unknown8-Jul-2002
Compaq Computer CorporationVulnerable16-Jul-2002
Computer AssociatesUnknown17-Jun-2002
CovalentVulnerable19-Jun-2002
Cray Inc.Not Vulnerable18-Jun-2002
Data GeneralUnknown17-Jun-2002
Debian LinuxVulnerable19-Jun-2002
F5 Networks, Inc.Vulnerable24-Jun-2002
FreeBSD, Inc.Vulnerable21-Jun-2002
FujitsuNot Vulnerable18-Jun-2002
Guardian Digital Inc. Vulnerable19-Jun-2002
Hewlett-Packard CompanyVulnerable15-Jul-2002
IBM CorporationVulnerable8-Aug-2002
IntelUnknown17-Jun-2002
Juniper Networks, Inc.Unknown17-Jun-2002
Lotus SoftwareNot Vulnerable18-Jun-2002
Lucent TechnologiesUnknown17-Jun-2002
Mandriva, Inc.Vulnerable21-Jun-2002
Mandriva, Inc.Vulnerable19-Jun-2002
Microsoft CorporationNot Vulnerable17-Jun-2002
NCSAUnknown17-Jun-2002
NEC CorporationUnknown17-Jun-2002
NETBSDUnknown17-Jun-2002
Network ApplianceVulnerable2-Nov-2007
Nortel Networks, Inc.Unknown27-Jun-2002
OpenBSDVulnerable21-Jun-2002
Oracle CorporationVulnerable21-Jun-2002
Red Hat, Inc.Vulnerable18-Jun-2002
Sequent Computer Systems, Inc.Unknown17-Jun-2002
SGIUnknown15-Jul-2002
SlackwareVulnerable21-Jun-2002
Sony CorporationUnknown17-Jun-2002
Sun Microsystems, Inc.Vulnerable24-Jun-2002
SUSE LinuxVulnerable19-Jun-2002
The SCO Group (SCO Linux)Vulnerable18-Sep-2002
The SCO Group (SCO Unix)Vulnerable18-Sep-2002
Trustix Secure LinuxVulnerable21-Jun-2002
Unisphere NetworksVulnerable27-Jun-2002
Wind River Systems, Inc.Unknown17-Jun-2002
Xerox CorporationVulnerable27-Mar-2003

References


http://httpd.apache.org/info/security_bulletin_20020617.txt
http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20502
http://www.ietf.org/rfc/rfc2068.txt
http://www.ietf.org/rfc/rfc2616.txt
http://www.linuxsecurity.com/articles/server_security_article-5150.html
http://www.ciac.org/ciac/bulletins/m-093.shtml
http://www.securityfocus.com/bid/5033
http://secunia.com/advisories/21917/

Credit

The CERT/CC thanks Mark Litchfield for reporting this vulnerability to the Apache Software Foundation, and Mark Cox for reporting this vulnerability to the CERT/CC.

This document was written by Cory F. Cohen.

Other Information

Date Public06/17/2002
Date First Published06/17/2002 09:38:30 PM
Date Last Updated11/02/2007
CERT AdvisoryCA-2002-17
CVE NameCVE-2002-0392
US-CERT Technical Alerts 
Metric53.35
Document Revision36

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader