Apache Mod_DAV LOCK Denial Of Service Vulnerability
BID:11185
Info
Apache Mod_DAV LOCK Denial Of Service Vulnerability
| Bugtraq ID: | 11185 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0809 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Julian Reschke <[email protected]> reported this vulnerability to the vendor. |
| Vulnerable: |
Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Home Trustix Secure Linux 2.1 Trustix Secure Linux 2.0 Trustix Secure Enterprise Linux 2.0 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 3 Redhat Desktop 3.0 IBM HTTP Server 2.0.47 .1 IBM HTTP Server 2.0.47 IBM HTTP Server 2.0.42 .2 IBM HTTP Server 2.0.42 .1 IBM HTTP Server 2.0.42 HP HP-UX B.11.23 HP HP-UX B.11.22 HP HP-UX B.11.11 HP HP-UX B.11.00 Gentoo Linux 1.4 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Apache Apache 2.0.50 Apache Apache 2.0.49 Apache Apache 2.0.48 Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.32 Apache Apache 2.0.28 Beta Apache Apache 2.0.28 Apache Apache 2.0 a9 Apache Apache 2.0 |
| Not Vulnerable: |
Apache Apache 2.0.51 |
Discussion
Apache Mod_DAV LOCK Denial Of Service Vulnerability
Apache's 'mod_dav' module is reported susceptible to a denial of service vulnerability.
This vulnerability presents itself when Apache is configured to use the 'mod_dav' module, and it receives a specific sequence of LOCK commands from an authorized user.
This vulnerability can be exploited by remote attackers to crash Apache processes. If Apache is configured to use the threaded process model, an attacker could completely crash Apache. If Apache is configured to use multiple processes as apposed to threads, an attacker could crash individual web server processes. With a sustained attack, they could crash multiple server processes, and still likely deny service to legitimate users.
All versions of Apache 2.0, prior to 2.0.51 are reported vulnerable.
Apache's 'mod_dav' module is reported susceptible to a denial of service vulnerability.
This vulnerability presents itself when Apache is configured to use the 'mod_dav' module, and it receives a specific sequence of LOCK commands from an authorized user.
This vulnerability can be exploited by remote attackers to crash Apache processes. If Apache is configured to use the threaded process model, an attacker could completely crash Apache. If Apache is configured to use multiple processes as apposed to threads, an attacker could crash individual web server processes. With a sustained attack, they could crash multiple server processes, and still likely deny service to legitimate users.
All versions of Apache 2.0, prior to 2.0.51 are reported vulnerable.
Exploit / POC
Apache Mod_DAV LOCK Denial Of Service Vulnerability
An exploit is not required. The reporter of this issue provided an example sequence of DAV commands sufficient to exploit this vulnerability:
MKCOL x
PUT x/y
LOCK x
LOCK x/y
An exploit is not required. The reporter of this issue provided an example sequence of DAV commands sufficient to exploit this vulnerability:
MKCOL x
PUT x/y
LOCK x
LOCK x/y
Solution / Fix
Apache Mod_DAV LOCK Denial Of Service Vulnerability
Solution:
Turbolinux has released advisory TLSA-2005-01-13 along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
Debian has released advisory DSA 558-1 along with fixes to address this issue for Debian systems. Please see the referenced advisory for further information.
RedHat has released advisory RHSA-2004:463-09 along with fixes to address these issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information.
Trustix Secure Linux has released an advisory (TSLSA-2004-0047) along with fixes dealing with this, and other issues. Please see the referenced advisory for further information.
Gentoo Linux has released advisory GLSA 200409-21 to address this, and other issues. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following with superuser privileges:
emerge sync
emerge -pv ">=net-www/apache-2.0.51"
emerge ">=net-www/apache-2.0.51"
emerge -pv ">=net-www/mod_dav-1.0.3-r2"
emerge ">=net-www/mod_dav-1.0.3-r2"
Conectiva Linux has released advisory CLA-2004:868 along with fixes to address this, and other issues. Please see the referenced advisory for further information.
Red Hat Fedora has released an advisory (FEDORA-2004-313) along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
The vendor has released version 2.0.51 to address this, and other issues:
HP has released an advisory (HPSBUX01090) to address various issues affecting HP-UX running Apache and PHP. Please see the referenced advisory for more information.
IBM has released an advisory dealing with this issue for the HTTP Server based on Apache. Please see the referenced advisory for more information.
Apache Apache 2.0
Apache Apache 2.0 a9
Apache Apache 2.0.28
Apache Apache 2.0.28 Beta
Apache Apache 2.0.32
Apache Apache 2.0.35
Apache Apache 2.0.36
Apache Apache 2.0.37
Apache Apache 2.0.38
Apache Apache 2.0.39
Apache Apache 2.0.40
Apache Apache 2.0.41
IBM HTTP Server 2.0.42 .2
Apache Apache 2.0.42
Apache Apache 2.0.43
Apache Apache 2.0.44
Apache Apache 2.0.45
Apache Apache 2.0.46
Apache Apache 2.0.47
IBM HTTP Server 2.0.47 .1
Apache Apache 2.0.48
Apache Apache 2.0.49
Apache Apache 2.0.50
Debian Linux 3.0 alpha
Debian Linux 3.0 mips
Debian Linux 3.0 m68k
Debian Linux 3.0 hppa
Debian Linux 3.0 arm
Debian Linux 3.0 ia-64
Debian Linux 3.0 ia-32
Solution:
Turbolinux has released advisory TLSA-2005-01-13 along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
Debian has released advisory DSA 558-1 along with fixes to address this issue for Debian systems. Please see the referenced advisory for further information.
RedHat has released advisory RHSA-2004:463-09 along with fixes to address these issues for RedHat Enterprise Linux operating systems. Please see the referenced advisory for further information.
Trustix Secure Linux has released an advisory (TSLSA-2004-0047) along with fixes dealing with this, and other issues. Please see the referenced advisory for further information.
Gentoo Linux has released advisory GLSA 200409-21 to address this, and other issues. Please see the referenced advisory for further information. Users of affected packages are urged to execute the following with superuser privileges:
emerge sync
emerge -pv ">=net-www/apache-2.0.51"
emerge ">=net-www/apache-2.0.51"
emerge -pv ">=net-www/mod_dav-1.0.3-r2"
emerge ">=net-www/mod_dav-1.0.3-r2"
Conectiva Linux has released advisory CLA-2004:868 along with fixes to address this, and other issues. Please see the referenced advisory for further information.
Red Hat Fedora has released an advisory (FEDORA-2004-313) along with fixes dealing with this and other issues. Please see the referenced advisory for more information.
The vendor has released version 2.0.51 to address this, and other issues:
HP has released an advisory (HPSBUX01090) to address various issues affecting HP-UX running Apache and PHP. Please see the referenced advisory for more information.
IBM has released an advisory dealing with this issue for the HTTP Server based on Apache. Please see the referenced advisory for more information.
Apache Apache 2.0
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0 a9
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.28
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.28 Beta
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.32
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.35
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.36
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.37
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.38
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.39
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.40
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.41
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
IBM HTTP Server 2.0.42 .2
-
IBM 2.0.42.2-PQ94389.aix.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.42.2-PQ94389.aix.tar -
IBM 2.0.42.2-PQ94389.hpux.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.42.2-PQ94389.hpux.tar -
IBM 2.0.42.2-PQ94389.linux.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.42.2-PQ94389.linux.tar -
IBM 2.0.42.2-PQ94389.linux390.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.42.2-PQ94389.linux390.tar -
IBM 2.0.42.2-PQ94389.linuxppc.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.42.2-PQ94389.linuxppc.tar -
IBM 2.0.42.2-PQ94389.nt.zip
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.42.2-PQ94389.nt.zip -
IBM 2.0.42.2-PQ94389.sun.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.42.2-PQ94389.sun.tar
Apache Apache 2.0.42
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.43
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.44
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz -
Conectiva apache-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-2.0.45-28790U90_8cl. i386.rpm -
Conectiva apache-devel-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-devel-2.0.45-28790U9 0_8cl.i386.rpm -
Conectiva apache-doc-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-doc-2.0.45-28790U90_ 8cl.i386.rpm -
Conectiva apache-htpasswd-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-htpasswd-2.0.45-2879 0U90_8cl.i386.rpm -
Conectiva libapr-devel-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-2.0.45-28790U9 0_8cl.i386.rpm -
Conectiva libapr-devel-static-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-static-2.0.45- 28790U90_8cl.i386.rpm -
Conectiva libapr0-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr0-2.0.45-28790U90_8cl .i386.rpm -
Conectiva mod_auth_ldap-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_auth_ldap-2.0.45-28790U 90_8cl.i386.rpm -
Conectiva mod_dav-2.0.45-28790U90_8cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_dav-2.0.45-28790U90_8cl .i386.rpm
Apache Apache 2.0.45
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.46
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Apache Apache 2.0.47
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
IBM HTTP Server 2.0.47 .1
-
IBM 2.0.47.1-PQ94389.aix.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.47.1-PQ94389.aix.tar -
IBM 2.0.47.1-PQ94389.hpux.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.47.1-PQ94389.hpux.tar -
IBM 2.0.47.1-PQ94389.linux.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.47.1-PQ94389.linux.tar -
IBM 2.0.47.1-PQ94389.linux390.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.47.1-PQ94389.linux390.tar -
IBM 2.0.47.1-PQ94389.linuxppc.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.47.1-PQ94389.linuxppc.tar -
IBM 2.0.47.1-PQ94389.nt.zip
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.47.1-PQ94389.nt.zip -
IBM 2.0.47.1-PQ94389.sun.tar
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PQ9438 9/2.0.47.1-PQ94389.sun.tar
Apache Apache 2.0.48
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz -
TurboLinux httpd-2.0.48-15.i586.rpm
ftp://ftp.turbolinux.co.jp/pub/TurboLinux/TurboLinux/ia32/Desktop/10/u pdates/RPMS/httpd-2.0.48-15.i586.rpm
Apache Apache 2.0.49
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz -
Conectiva apache-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-2.0.49-61251U10_1cl .i386.rpm -
Conectiva apache-devel-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-devel-2.0.49-61251U 10_1cl.i386.rpm -
Conectiva apache-doc-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-doc-2.0.49-61251U10 _1cl.i386.rpm -
Conectiva apache-htpasswd-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/apache-htpasswd-2.0.49-612 51U10_1cl.i386.rpm -
Conectiva libapr-devel-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libapr-devel-2.0.49-61251U 10_1cl.i386.rpm -
Conectiva libapr-devel-static-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libapr-devel-static-2.0.49 -61251U10_1cl.i386.rpm -
Conectiva libapr0-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/libapr0-2.0.49-61251U10_1c l.i386.rpm -
Conectiva mod_auth_ldap-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mod_auth_ldap-2.0.49-61251 U10_1cl.i386.rpm -
Conectiva mod_dav-2.0.49-61251U10_1cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/10/RPMS/mod_dav-2.0.49-61251U10_1c l.i386.rpm -
Fedora httpd-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-debuginfo-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-debuginfo-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-devel-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-devel-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-manual-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora httpd-manual-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora mod_ssl-2.0.51-2.7.i386.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Fedora mod_ssl-2.0.51-2.7.x86_64.rpm
RedHat Fedora Core 2
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/ -
Trustix apache-2.0.51-0.1tr.i586.rpm
Trustix Secure Linux 2.0, 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-devel-2.0.51-0.1tr.i586.rpm
Trustix Secure Linux 2.0, 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix apache-manual-2.0.51-0.1tr.i586.rpm
Trustix Secure Linux 2.0, 2.1 & Enterprise Server 2
ftp://ftp.trustix.org/pub/trustix/updates/
Apache Apache 2.0.50
-
Apache Software Foundation httpd-2.0.51.tar.gz
http://www.apache.org/dist/httpd/httpd-2.0.51.tar.gz
Debian Linux 3.0 alpha
-
Debian libapache-mod-dav_1.0.3-3.1_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/liba/libapache-mod-dav/li bapache-mod-dav_1.0.3-3.1_alpha.deb
Debian Linux 3.0 mips
-
Debian libapache-mod-dav_1.0.3-3.1_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/liba/libapache-mod-dav_1. 0.3-3.1_mips.deb
Debian Linux 3.0 m68k
-
Debian libapache-mod-dav_1.0.3-3.1_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/liba/libapache-mod-dav_1. 0.3-3.1_m68k.deb
Debian Linux 3.0 hppa
-
Debian libapache-mod-dav_1.0.3-3.1_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/liba/libapache-mod-dav_1. 0.3-3.1_hppa.deb
Debian Linux 3.0 arm
-
Debian libapache-mod-dav_1.0.3-3.1_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/liba/libapache-mod-dav_1. 0.3-3.1_arm.deb
Debian Linux 3.0 ia-64
-
Debian libapache-mod-dav_1.0.3-3.1_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/liba/libapache-mod-dav_1. 0.3-3.1_ia64.deb
Debian Linux 3.0 ia-32
-
Debian libapache-mod-dav_1.0.3-3.1_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/liba/libapache-mod-dav_1. 0.3-3.1_i386.deb
References
Apache Mod_DAV LOCK Denial Of Service Vulnerability
References:
References:
- Apache 2.0.x Latest Release Information Page (Apache Software Foundation)
- Apache Homepage (Apache Software Foundation)
- Bug 31183 - LOCK refresh request crashes server (Apache Software Foundation)
- New Denial of Service exposures for releases of IBM HTTP Server V2.0 (IBM)
- RHSA-2004:463-09 - Updated httpd packages fix security issues (RedHat)
- [ANNOUNCE] Apache HTTP Server 2.0.51 Released (Apache Software Foundation)