Apache Web Server Chunk Handling Vulnerability

A vulnerability exists in Apache Web servers that can lead to arbitrary code execution on the vulnerable system.

Ken Pfeil

June 18, 2002

1 Min Read
ITPro Today logo

ReportedJune 17, 2002, by CERT.

VERSIONS AFFECTED

 

  • Apache 2, all versions up to 2.0.36

  • Apache 1.3, all versions including 1.3.24

  • Apache 1.2, all versions 1.2.2 and later

 

DESCRIPTION

A vulnerability exists in Apache Web servers that can leadto arbitrary code execution on the vulnerable system. This vulnerability stemsfrom a flaw in the handling of certain chunk-encoded HTTPrequests that lets a remote attacker execute arbitrary code or cause a Denial ofService (DoS) attack.

VENDOR RESPONSE

The vendor, Apache,has released a detailedadvisory about this vulnerability and recommends that affected users eitherapply a patch supplied by an OEM or upgrade immediately to a newer version ofApache software available from Apache's Website.

 

CREDIT
Discovered by MarkLitchfield of Next Generation SecuritySoftware.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like