Apache Web Server Chunk Handling Vulnerability
A vulnerability exists in Apache Web servers that can lead to arbitrary code execution on the vulnerable system.
June 18, 2002
ReportedJune 17, 2002, by CERT.
VERSIONS AFFECTED
Apache 2, all versions up to 2.0.36
Apache 1.3, all versions including 1.3.24
Apache 1.2, all versions 1.2.2 and later
DESCRIPTION
A vulnerability exists in Apache Web servers that can leadto arbitrary code execution on the vulnerable system. This vulnerability stemsfrom a flaw in the handling of certain chunk-encoded HTTPrequests that lets a remote attacker execute arbitrary code or cause a Denial ofService (DoS) attack.
VENDOR RESPONSE
The vendor, Apache,has released a detailedadvisory about this vulnerability and recommends that affected users eitherapply a patch supplied by an OEM or upgrade immediately to a newer version ofApache software available from Apache's Website.
CREDIT
Discovered by MarkLitchfield of Next Generation SecuritySoftware.
About the Author
You May Also Like