CVE-2006-3747
Summary
| CVE | CVE-2006-3747 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-28 18:02:00 UTC |
| Updated | 2023-02-13 02:16:00 UTC |
| Description | Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules. |
Risk And Classification
Problem Types: CWE-189
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | All | All | All | All |
| Application | Apache | Http Server | 1.3.28 | All | All | All |
| Application | Apache | Http Server | 1.3.29 | All | All | All |
| Application | Apache | Http Server | 1.3.3 | All | All | All |
| Application | Apache | Http Server | 1.3.30 | All | All | All |
| Application | Apache | Http Server | 1.3.31 | All | All | All |
| Application | Apache | Http Server | 1.3.32 | All | All | All |
| Application | Apache | Http Server | 1.3.33 | All | All | All |
| Application | Apache | Http Server | 1.3.4 | All | All | All |
| Application | Apache | Http Server | 1.3.5 | All | All | All |
| Application | Apache | Http Server | 1.3.6 | All | All | All |
| Application | Apache | Http Server | 1.3.7 | All | All | All |
| Application | Apache | Http Server | 1.3.7 | All | dev | All |
| Application | Apache | Http Server | 1.3.8 | All | All | All |
| Application | Apache | Http Server | 1.3.9 | All | All | All |
| Application | Apache | Http Server | 2.0.46 | All | All | All |
| Application | Apache | Http Server | 2.0.47 | All | All | All |
| Application | Apache | Http Server | 2.0.48 | All | All | All |
| Application | Apache | Http Server | 2.0.49 | All | All | All |
| Application | Apache | Http Server | 2.0.50 | All | All | All |
| Application | Apache | Http Server | 2.0.51 | All | All | All |
| Application | Apache | Http Server | 2.0.52 | All | All | All |
| Application | Apache | Http Server | 2.0.53 | All | All | All |
| Application | Apache | Http Server | 2.0.54 | All | All | All |
| Application | Apache | Http Server | 2.0.55 | All | All | All |
| Application | Apache | Http Server | 2.0.56 | All | All | All |
| Application | Apache | Http Server | 2.0.57 | All | All | All |
| Application | Apache | Http Server | 2.0.58 | All | All | All |
| Application | Apache | Http Server | 1.3.28 | All | All | All |
| Application | Apache | Http Server | 1.3.29 | All | All | All |
| Application | Apache | Http Server | 1.3.3 | All | All | All |
| Application | Apache | Http Server | 1.3.30 | All | All | All |
| Application | Apache | Http Server | 1.3.31 | All | All | All |
| Application | Apache | Http Server | 1.3.32 | All | All | All |
| Application | Apache | Http Server | 1.3.33 | All | All | All |
| Application | Apache | Http Server | 1.3.4 | All | All | All |
| Application | Apache | Http Server | 1.3.5 | All | All | All |
| Application | Apache | Http Server | 1.3.6 | All | All | All |
| Application | Apache | Http Server | 1.3.7 | All | All | All |
| Application | Apache | Http Server | 1.3.7 | All | dev | All |
| Application | Apache | Http Server | 1.3.8 | All | All | All |
| Application | Apache | Http Server | 1.3.9 | All | All | All |
| Application | Apache | Http Server | 2.0.46 | All | All | All |
| Application | Apache | Http Server | 2.0.47 | All | All | All |
| Application | Apache | Http Server | 2.0.48 | All | All | All |
| Application | Apache | Http Server | 2.0.49 | All | All | All |
| Application | Apache | Http Server | 2.0.50 | All | All | All |
| Application | Apache | Http Server | 2.0.51 | All | All | All |
| Application | Apache | Http Server | 2.0.52 | All | All | All |
| Application | Apache | Http Server | 2.0.53 | All | All | All |
| Application | Apache | Http Server | 2.0.54 | All | All | All |
| Application | Apache | Http Server | 2.0.55 | All | All | All |
| Application | Apache | Http Server | 2.0.56 | All | All | All |
| Application | Apache | Http Server | 2.0.57 | All | All | All |
| Application | Apache | Http Server | 2.0.58 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 5.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 5.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Debian | Debian Linux | 3.1 | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 5.04 | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 5.10 | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 6.06_lts | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 5.04 | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 5.10 | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 6.06_lts | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Apache mod_rewrite Off-by-one Error Lets Remote Users Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| SUSE update for apache - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityFocus | HP | www.securityfocus.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Apache HTTP Server Project | CONFIRM | www.apache.org | Patch, Vendor Advisory |
| Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability | BID | www.securityfocus.com | |
| Debian -- Security Information -- DSA-1132-1 apache2 | DEBIAN | www.debian.org | Patch |
| HP System Management Homepage Apache and OpenSSL Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| About Security Update 2008-002 | CONFIRM | docs.info.apple.com | |
| SecurityReason - Apache mod_rewrite Buffer Overflow Vulnerability | SREASON | securityreason.com | |
| Gentoo Linux Documentation -- Apache: Off-by-one flaw in mod_rewrite | GENTOO | security.gentoo.org | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| HP-UX update for Apache - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Secunia - Advisories - Trustix updates for multiple packages | SECUNIA | secunia.com | Vendor Advisory |
| 27588 | OSVDB | www.osvdb.org | |
| IBM WebSphere Application Server Apache mod_rewrite Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| HPSBMA02328 SSRT071293 rev.2 - HP OpenView Network Node Manager (OV NNM) Running Apache, Remote Cross Site Scripting (XSS), Denial of Service (DoS), Execute Arbitrary Code - c01428449 - HP Business Support Center | HP | h20000.www2.hp.com | |
| IBM Fix list for IBM WebSphere Application Server V6.1 - United States | CONFIRM | www-1.ibm.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Debian update for apache - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| [Apache-SVN] Revision 426144 | MISC | svn.apache.org | |
| Pony Mail! | MISC | lists.apache.org | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| SecurityFocus | HP | www.securityfocus.com | |
| Pony Mail! | MISC | lists.apache.org | |
| Pony Mail! | MISC | lists.apache.org | |
| IBM HTTP Server Apache mod_rewrite Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| IBM WebSphere Application Server Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Sun Solaris Apache "mod_rewrite" and "mod_imap" Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Pony Mail! | MISC | lists.apache.org | |
| Pony Mail! | MISC | lists.apache.org | |
| IBM PK29154: CVE-2006-3747 MOD_REWRITE ERROR - United States | AIXAPAR | www-1.ibm.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Apache mod_rewrite Off-By-One Buffer Overflow Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Pony Mail! | MISC | lists.apache.org | |
| 404 Content not found errors - SunSolve - wikis.sun.com | SUNALERT | sunsolve.sun.com | |
| [Full-disclosure] [Announcement] Apache HTTP Server 2.2.3 (2.0.59, 1.3.37) Released | FULLDISC | lists.grok.org.uk | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MISC | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-1.ibm.com | |
| Security Announcement | SUSE | www.novell.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Ubuntu update for apache - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| HP OpenView Network Node Manager Multiple Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| '[security bulletin] HPSBOV02683 SSRT090208 rev.1 - HP Secure Web Server (SWS) for OpenVMS running Ap' - MARC | HP | marc.info | |
| Mandriva update for apache - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Pony Mail! | MLIST | lists.apache.org | |
| [#RPL-538] Apache httpd mod_rewrite remote code execution exploit CVE-2006-3747 - rPath JIRA | CONFIRM | issues.rpath.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| HPSBMA02250 SSRT061275 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Execution of Arbitrary Code and Denial of Service (DoS) - c01118771 - HP Business Support Center | HP | h20000.www2.hp.com | |
| Advisories - Mandriva Linux | MANDRIVA | www.mandriva.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Debian -- Security Information -- DSA-1131-1 apache | DEBIAN | www.debian.org | Patch |
| IBM - Subscription service - Bulletin | CONFIRM | www14.software.ibm.com | |
| #102662: Security Vulnerabilities in the Apache 2.0 Web Server "mod_rewrite" Module | SUNALERT | sunsolve.sun.com | |
| [Full-disclosure] Apache 1.3.29/2.X mod_rewrite Buffer Overflow Vulnerability CVE-2006-3747 | FULLDISC | lists.grok.org.uk | |
| Pony Mail! | MISC | lists.apache.org | |
| Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| Pony Mail! | MISC | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Trustix alert TSLSA-2006-0044 (apache, gnupg, libtiff) [LWN.net] | TRUSTIX | lwn.net | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-1.ibm.com | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| usn/usn-328-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | |
| US-CERT Technical Cyber Security Alert TA08-150A -- Apple Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| Sun Solaris update for Apache 2 - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Gentoo update for apache - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| OpenPKG Corporation: Security: Security Advisories | OPENPKG | www.openpkg.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Debian update for apache2 - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| IBM HTTP Server Two Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Slackware update for apache - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | SECUNIA | secunia.com | |
| IBM HMC Apache2 / OpenSSL Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| redhat.com | Knowledgebase | MISC | kbase.redhat.com | |
| Pony Mail! | MISC | lists.apache.org | |
| Pony Mail! | MISC | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MISC | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| rPath update for httpd and mod_ssl - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| OpenBSD update for httpd - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| APPLE-SA-2008-05-28 Security Update 2008-003 and Mac OS X v10.5.3 | APPLE | lists.apple.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| APPLE-SA-2008-03-18 Security Update 2008-002 | APPLE | lists.apple.com | |
| Pony Mail! | MISC | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MISC | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| VU#395412 - Apache mod_rewrite contains off-by-one error in ldap scheme handling | CERT-VN | www.kb.cert.org | US Government Resource |
| Pony Mail! | MLIST | lists.apache.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Apache | 2008-07-02 | Mark J Cox | Fixed in Apache HTTP Server 2.2.3, 2.0.59, and 1.3.37: http://httpd.apache.org/security/vulnerabilities_22.html http://httpd.apache.org/security/vulnerabilities_20.html http://httpd.apache.org/security/vulnerabilities_13.html |
| Red Hat | 2006-07-31 | Mark J Cox | The ability to exploit this issue is dependent on the stack layout for a particular compiled version of mod_rewrite. If the compiler has added padding to the stack immediately after the buffer being overwritten, this issue can not be exploited, and Apache httpd will continue operating normally. The Red Hat Security Response Team analyzed Red Hat Enterprise Linux 3 and Red Hat Enterprise Linux 4 binaries for all architectures as shipped by Red Hat and determined that these versions cannot be exploited. This issue does not affect the version of Apache httpd as supplied with Red Hat Enterprise Linux 2.1 |
There are currently no legacy QID mappings associated with this CVE.