Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
BID:10619
Info
Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
| Bugtraq ID: | 10619 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0493 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2004 12:00AM |
| Updated: | Aug 05 2010 07:46PM |
| Credit: | Discovery of this issue is credited to Georgi Guninski <[email protected]>. |
| Vulnerable: |
Trustix Secure Linux 2.1 Trustix Secure Linux 2.0 Trustix Secure Linux 1.5 Trustix Secure Enterprise Linux 2.0 IBM HTTP Server 2.0.47 .1 IBM HTTP Server 2.0.47 IBM HTTP Server 2.0.42 .2 IBM HTTP Server 2.0.42 .1 IBM HTTP Server 2.0.42 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 Gentoo Linux 1.4 Avaya S8700 R2.0.0 Avaya S8500 R2.0.0 Avaya S8300 R2.0.0 Avaya Converged Communications Server 2.0 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.2.8 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.2.8 Apache Apache 2.0.49 Apache Apache 2.0.48 Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.32 Apache Apache 2.0.28 Beta Apache Apache 2.0.28 Apache Apache 2.0 a9 Apache Apache 2.0 |
| Not Vulnerable: |
Apache Apache 2.0.50 Apache Apache 1.3.31 Apache Apache 1.3.29 Apache Apache 1.3.28 Apache Apache 1.3.27 Apache Apache 1.3.26 Apache Apache 1.3.25 Apache Apache 1.3.24 Apache Apache 1.3.23 Apache Apache 1.3.22 Apache Apache 1.3.20 Apache Apache 1.3.19 Apache Apache 1.3.18 Apache Apache 1.3.17 Apache Apache 1.3.14 Apache Apache 1.3.12 Apache Apache 1.3.11 Apache Apache 1.3.9 Apache Apache 1.3.7 -dev Apache Apache 1.3.6 Apache Apache 1.3.4 Apache Apache 1.3.3 Apache Apache 1.3.1 Apache Apache 1.3 |
Discussion
Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
Apache Web Server is reportedly affected by a memory allocation based denial of service vulnerability. This issue is due to a failure of the server to handle excessivley long HTTP header strings.
This issue would allow an attacker to cause the affected application to crash, denying service to legitimate users.
Although Apache version 2.0.49 reportedly affected by this issue, it is likely that earlier versions are affected as well.
Apache Web Server is reportedly affected by a memory allocation based denial of service vulnerability. This issue is due to a failure of the server to handle excessivley long HTTP header strings.
This issue would allow an attacker to cause the affected application to crash, denying service to legitimate users.
Although Apache version 2.0.49 reportedly affected by this issue, it is likely that earlier versions are affected as well.
Exploit / POC
Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
The following proof of concept is made available by bkbll <[email protected]>:
The following proof of concept is made available by bkbll <[email protected]>:
Solution / Fix
Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
Solution:
A patch is available from the Apache Software Foundation.
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Mandrake has released a security advisory (MDKSA-2004:064) to address this issue. Information on obtaining fixes and updating packages can be found in the referenced advisory.
Trustix Secure Linux has released advisories TSL-2004-0038, and TSL-2004-0039 to address this, and other issues. Please see the referenced advisories for further information.
Gentoo Linux has released advisory GLSA 200407-03 to address this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following as the superuser:
emerge sync
emerge -pv ">=net-www/apache-2.0.49-r4"
emerge ">=net-www/apache-2.0.49-r4"
Red Hat has released advisory RHSA-2004:342-10 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
The Apache Software Foundation has released Apache 2.0.50 that includes a fix for this issue.
Avaya has released an updated advisory that acknowledges this vulnerability for Avaya products. Fixes are not currently available; customers are advised to contact the vendor for further details regarding fix availability. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=196012&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Red Hat Fedora has released advisories FEDORA-2004-203 and FEDORA-2004-204 dealing with this issue for Fedora Core 1 and Fedora Core 2 respectively. Please see the referenced advisories for more information.
Hewlett-Packard has released advisory HPSBUX01064 along with a resolution dealing with this issue. Please see the referenced advisory for more information.
Conectiva Linux has released advisory CLA-2004:868 along with fixes to address this, and other issues. Please see the referenced advisory for further information.
HP HP-UX B.11.22
HP HP-UX B.11.23
HP HP-UX B.11.11
HP HP-UX B.11.00
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X 10.3.4
Apple Mac OS X Server 10.3.4
Apple Mac OS X Server 10.3.5
Apple Mac OS X 10.3.5
Apache Apache 2.0
Apache Apache 2.0 a9
Apache Apache 2.0.28
Apache Apache 2.0.28 Beta
Apache Apache 2.0.32
Apache Apache 2.0.35
Apache Apache 2.0.36
Apache Apache 2.0.37
Apache Apache 2.0.38
Apache Apache 2.0.39
Apache Apache 2.0.40
Apache Apache 2.0.41
IBM HTTP Server 2.0.42 .2
Apache Apache 2.0.42
Apache Apache 2.0.43
Apache Apache 2.0.44
Apache Apache 2.0.45
Apache Apache 2.0.46
Apache Apache 2.0.47
IBM HTTP Server 2.0.47 .1
Apache Apache 2.0.48
Apache Apache 2.0.49
Solution:
A patch is available from the Apache Software Foundation.
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Mandrake has released a security advisory (MDKSA-2004:064) to address this issue. Information on obtaining fixes and updating packages can be found in the referenced advisory.
Trustix Secure Linux has released advisories TSL-2004-0038, and TSL-2004-0039 to address this, and other issues. Please see the referenced advisories for further information.
Gentoo Linux has released advisory GLSA 200407-03 to address this issue. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following as the superuser:
emerge sync
emerge -pv ">=net-www/apache-2.0.49-r4"
emerge ">=net-www/apache-2.0.49-r4"
Red Hat has released advisory RHSA-2004:342-10 and fixes to address this issue on Red Hat Linux Enterprise platforms. Customers who are affected by this issue are advised to apply the appropriate updates. Customers subscribed to the Red Hat Network may apply the appropriate fixes using the Red Hat Update Agent (up2date). Please see referenced advisory for additional information.
The Apache Software Foundation has released Apache 2.0.50 that includes a fix for this issue.
Avaya has released an updated advisory that acknowledges this vulnerability for Avaya products. Fixes are not currently available; customers are advised to contact the vendor for further details regarding fix availability. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=196012&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Red Hat Fedora has released advisories FEDORA-2004-203 and FEDORA-2004-204 dealing with this issue for Fedora Core 1 and Fedora Core 2 respectively. Please see the referenced advisories for more information.
Hewlett-Packard has released advisory HPSBUX01064 along with a resolution dealing with this issue. Please see the referenced advisory for more information.
Conectiva Linux has released advisory CLA-2004:868 along with fixes to address this, and other issues. Please see the referenced advisory for further information.
HP HP-UX B.11.22
-
HP HP-UX Apache-based Web Server v.2.0.50.00
http://software.hp.com
HP HP-UX B.11.23
-
HP HP-UX Apache-based Web Server v.2.0.50.00
http://software.hp.com
HP HP-UX B.11.11
-
HP HP-UX Apache-based Web Server v.2.0.50.00
http://software.hp.com
HP HP-UX B.11.00
-
HP HP-UX Apache-based Web Server v.2.0.50.00
http://software.hp.com
Apple Mac OS X 10.2.8
-
Apple SecUpd2004-02-23Jag.dmg
http://www.info.apple.com/kbnum/n120277 -
Apple SecUpd2004-09-07JagClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04717&plat form=osx&method=sa/SecUpd2004-09-07JagClient.dmg
Apple Mac OS X Server 10.2.8
-
Apple SecUpdSrvr2004-09-07Jag.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04716&plat form=osx&method=sa/SecUpdSrvr2004-09-07Jag.dmg
Apple Mac OS X 10.3.4
-
Apple SecUpd2004-09-07PanClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04712&plat form=osx&method=sa/SecUpd2004-09-07PanClient.dmg
Apple Mac OS X Server 10.3.4
-
Apple SecUpdSrvr2004-09-07PanL.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04713&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanL.dmg
Apple Mac OS X Server 10.3.5
-
Apple SecUpdSrvr2004-09-07PanM.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04714&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanM.dmg
Apple Mac OS X 10.3.5
-
Apple SecUpd2004-09-07PanMClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04715&plat form=osx&method=sa/SecUpd2004-09-07PanMClient.dmg
Apache Apache 2.0
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0 a9
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.28
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.28 Beta
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.32
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.35
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.36
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.37
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.38
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.39
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.40
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.41
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
IBM HTTP Server 2.0.42 .2
-
IBM 2.0.42.2-PQ90698.aix.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.42.2-PQ90698.aix.tar -
IBM 2.0.42.2-PQ90698.hpux.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.42.2-PQ90698.hpux.tar -
IBM 2.0.42.2-PQ90698.linux.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.42.2-PQ90698.linux.tar -
IBM 2.0.42.2-PQ90698.linux390.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.42.2-PQ90698.linux390.tar -
IBM 2.0.42.2-PQ90698.linuxppc.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.42.2-PQ90698.linuxppc.tar -
IBM 2.0.42.2-PQ90698.nt.zip
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.42.2-PQ90698.nt.zip -
IBM 2.0.42.2-PQ90698.sun.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.42.2-PQ90698.sun.tar
Apache Apache 2.0.42
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.43
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.44
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz -
Conectiva apache-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-2.0.45-28790U90_8cl. i386.rpm -
Conectiva apache-devel-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-devel-2.0.45-28790U9 0_8cl.i386.rpm -
Conectiva apache-doc-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-doc-2.0.45-28790U90_ 8cl.i386.rpm -
Conectiva apache-htpasswd-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-htpasswd-2.0.45-2879 0U90_8cl.i386.rpm -
Conectiva libapr-devel-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-2.0.45-28790U9 0_8cl.i386.rpm -
Conectiva libapr-devel-static-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-static-2.0.45- 28790U90_8cl.i386.rpm -
Conectiva libapr0-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr0-2.0.45-28790U90_8cl .i386.rpm -
Conectiva mod_auth_ldap-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_auth_ldap-2.0.45-28790U 90_8cl.i386.rpm -
Conectiva mod_dav-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_dav-2.0.45-28790U90_8cl .i386.rpm
Apache Apache 2.0.45
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.46
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz
Apache Apache 2.0.47
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz -
Fedora httpd-2.0.50-1.0.i386.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora httpd-debuginfo-2.0.50-1.0.i386.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora httpd-devel-2.0.50-1.0.i386.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora httpd-manual-2.0.50-1.0.i386.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora mod_ssl-2.0.50-1.0.i386.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Mandrake apache2-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64apr0-2.0.47-6.6.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-1.9.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-1.9.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.47-6.6.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php
IBM HTTP Server 2.0.47 .1
-
IBM 2.0.47.1-PQ90698.aix.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.47.1-PQ90698.aix.tar -
IBM 2.0.47.1-PQ90698.hpux.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.47.1-PQ90698.hpux.tar -
IBM 2.0.47.1-PQ90698.linux.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.47.1-PQ90698.linux.tar -
IBM 2.0.47.1-PQ90698.linux390.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.47.1-PQ90698.linux390.tar -
IBM 2.0.47.1-PQ90698.linuxppc.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.47.1-PQ90698.linuxppc.tar -
IBM 2.0.47.1-PQ90698.nt.zip
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.47.1-PQ90698.nt.zip -
IBM 2.0.47.1-PQ90698.sun.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9069 8/2.0.47.1-PQ90698.sun.tar
Apache Apache 2.0.48
-
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz -
Fedora httpd-2.0.50-1.0.x86_64.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora httpd-debuginfo-2.0.50-1.0.x86_64.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora httpd-devel-2.0.50-1.0.x86_64.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora httpd-manual-2.0.50-1.0.x86_64.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Fedora mod_ssl-2.0.50-1.0.x86_64.rpm
RedHat Fedora Core 1
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/ -
Mandrake apache2-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-common-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-devel-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-manual-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_cache-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_dav-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_deflate-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_disk_cache-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_file_cache-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ldap-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_mem_cache-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_proxy-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-mod_ssl-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-modules-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache2-source-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake lib64apr0-2.0.48-6.3.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake libapr0-2.0.48-6.3.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php
Apache Apache 2.0.49
-
Apache Software Foundation CAN-2004-0493.patch
http://www.apache.org/dist/httpd/patches/apply_to_2.0.49/CAN-2004-0493 .patch -
Apache Software Foundation httpd-2.0.50.tar.gz
http://www.tux.org/pub/net/apache/dist/httpd/httpd-2.0.50.tar.gz -
Conectiva apache-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-2.0.49-61251U10_1cl .i386.rpm -
Conectiva apache-devel-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-devel-2.0.49-61251U 10_1cl.i386.rpm -
Conectiva apache-doc-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-doc-2.0.49-61251U10 _1cl.i386.rpm -
Conectiva apache-htpasswd-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-htpasswd-2.0.49-612 51U10_1cl.i386.rpm -
Conectiva libapr-devel-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libapr-devel-2.0.49-61251U 10_1cl.i386.rpm -
Conectiva libapr-devel-static-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libapr-devel-static-2.0.49 -61251U10_1cl.i386.rpm -
Conectiva libapr0-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libapr0-2.0.49-61251U10_1c l.i386.rpm -
Conectiva mod_auth_ldap-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mod_auth_ldap-2.0.49-61251 U10_1cl.i386.rpm -
Conectiva mod_dav-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mod_dav-2.0.49-61251U10_1c l.i386.rpm -
Fedora httpd-2.0.50-2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-2.0.50-2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-debuginfo-2.0.50-2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-debuginfo-2.0.50-2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-devel-2.0.50-2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-devel-2.0.50-2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-manual-2.0.50-2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-manual-2.0.50-2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora mod_ssl-2.0.50-2.1.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora mod_ssl-2.0.50-2.1.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Trustix apache-2.0.49-4tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-2.0.49-9tr.i586.rpm
Trustix Secure Linux 2.1 & Trustix Operating System - Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-2.0.50-1tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-2.0.50-2tr.i586.rpm
Trustix Secure Linux 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-dbm-2.0.49-9tr.i586.rpm
Trustix Secure Linux 2.1 & Trustix Operating System - Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-dbm-2.0.50-2tr.i586.rpm
Trustix Secure Linux 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-devel-2.0.49-4tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-devel-2.0.49-9tr.i586.rpm
Trustix Secure Linux 2.1 & Trustix Operating System - Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-devel-2.0.50-1tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-devel-2.0.50-2tr.i586.rpm
Trustix Secure Linux 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-manual-2.0.49-4tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-manual-2.0.49-9tr.i586.rpm
Trustix Secure Linux 2.1 & Trustix Operating System - Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-manual-2.0.50-1tr.i586.rpm
Trustix Secure Linux 2.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-manual-2.0.50-2tr.i586.rpm
Trustix Secure Linux 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/
References
Apache ap_escape_html Memory Allocation Denial Of Service Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- PQ90698 - Potential denial of service exposure (IBM)
- RHSA-2004:342-10 - Updated httpd packages fix security issues (RedHat)