Apache MPM Worker.C Denial Of Service Vulnerability
BID:15762
Info
Apache MPM Worker.C Denial Of Service Vulnerability
| Bugtraq ID: | 15762 |
| Class: | Design Error |
| CVE: |
CVE-2005-2970 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2005 12:00AM |
| Updated: | Dec 15 2006 11:33PM |
| Credit: | Filip Sneppe is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat 7.0 traceroute 1.4 a5 IBM HTTP Server 2.0.47 .1 IBM HTTP Server 2.0.47 IBM HTTP Server 2.0.42 .2 IBM HTTP Server 2.0.42 .1 IBM HTTP Server 2.0.42 Apache Cocoon 2.1 Apache Apache 2.0.54 Apache Apache 2.0.53 Apache Apache 2.0.52 Apache Apache 2.0.51 Apache Apache 2.0.50 Apache Apache 2.0.49 Apache Apache 2.0.48 Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.32 Apache Apache 2.0.28 Beta Apache Apache 2.0.28 Apache Apache 2.0 a9 Apache Apache 2.0 |
| Not Vulnerable: |
Apache Apache 2.0.55 |
Discussion
Apache MPM Worker.C Denial Of Service Vulnerability
Apache is prone to a memory leak that may cause a denial-of-service condition.
An attacker may consume excessive memory resources, resulting in a denial of service for legitimate users.
Apache 2.x versions are vulnerable; other versions may also be affected.
Apache is prone to a memory leak that may cause a denial-of-service condition.
An attacker may consume excessive memory resources, resulting in a denial of service for legitimate users.
Apache 2.x versions are vulnerable; other versions may also be affected.
Exploit / POC
Apache MPM Worker.C Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Apache MPM Worker.C Denial Of Service Vulnerability
Solution:
Please see the referenced vendor advisories for more information and fixes.
Apache Apache 2.0.40
Apache Apache 2.0.47
Apache Apache 2.0.49
Apache Apache 2.0.52
Apache Apache 2.0.54
Solution:
Please see the referenced vendor advisories for more information and fixes.
Apache Apache 2.0.40
-
RedHat httpd-2.0.40-21.21.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/httpd-2.0.40-21 .21.legacy.i386.rpm -
RedHat httpd-devel-2.0.40-21.21.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/httpd-devel-2.0 .40-21.21.legacy.i386.rpm -
RedHat httpd-manual-2.0.40-21.21.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/httpd-manual-2. 0.40-21.21.legacy.i386.rpm -
RedHat mod_ssl-2.0.40-21.21.legacy.i386.rpm
Red Hat Linux 9:
http://download.fedoralegacy.org/redhat/9/updates/i386/mod_ssl-2.0.40- 21.21.legacy.i386.rpm
Apache Apache 2.0.47
-
RedHat httpd-2.0.51-1.10.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/httpd-2.0.51-1. 10.legacy.i386.rpm -
RedHat httpd-devel-2.0.51-1.10.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/httpd-devel-2.0 .51-1.10.legacy.i386.rpm -
RedHat httpd-manual-2.0.51-1.10.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/httpd-manual-2. 0.51-1.10.legacy.i386.rpm -
RedHat mod_ssl-2.0.51-1.10.legacy.i386.rpm
Fedora Core 1:
http://download.fedoralegacy.org/fedora/1/updates/i386/mod_ssl-2.0.51- 1.10.legacy.i386.rpm
Apache Apache 2.0.49
-
RedHat httpd-2.0.51-2.9.5.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/httpd-2.0.51-2. 9.5.legacy.i386.rpm -
RedHat httpd-devel-2.0.51-2.9.5.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/httpd-devel-2.0 .51-2.9.5.legacy.i386.rpm -
RedHat httpd-manual-2.0.51-2.9.5.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/httpd-manual-2. 0.51-2.9.5.legacy.i386.rpm -
RedHat mod_ssl-2.0.51-2.9.5.legacy.i386.rpm
Fedora Core 2:
http://download.fedoralegacy.org/fedora/2/updates/i386/mod_ssl-2.0.51- 2.9.5.legacy.i386.rpm
Apache Apache 2.0.52
-
RedHat httpd-2.0.53-3.4.legacy.i386.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/httpd-2.0.53-3. 4.legacy.i386.rpm -
RedHat httpd-2.0.53-3.4.legacy.x86_64.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/httpd-2.0.53- 3.4.legacy.x86_64.rpm -
RedHat httpd-devel-2.0.53-3.4.legacy.i386.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/httpd-devel-2.0 .53-3.4.legacy.i386.rpm -
RedHat httpd-devel-2.0.53-3.4.legacy.x86_64.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/httpd-devel-2 .0.53-3.4.legacy.x86_64.rpm -
RedHat httpd-manual-2.0.53-3.4.legacy.i386.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/httpd-manual-2. 0.53-3.4.legacy.i386.rpm -
RedHat httpd-manual-2.0.53-3.4.legacy.x86_64.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/httpd-manual- 2.0.53-3.4.legacy.x86_64.rpm -
RedHat httpd-suexec-2.0.53-3.4.legacy.i386.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/httpd-suexec-2. 0.53-3.4.legacy.i386.rpm -
RedHat httpd-suexec-2.0.53-3.4.legacy.x86_64.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/httpd-suexec- 2.0.53-3.4.legacy.x86_64.rpm -
RedHat mod_ssl-2.0.53-3.4.legacy.i386.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/i386/mod_ssl-2.0.53- 3.4.legacy.i386.rpm -
RedHat mod_ssl-2.0.53-3.4.legacy.x86_64.rpm
Fedora Core 3:
http://download.fedoralegacy.org/fedora/3/updates/x86_64/mod_ssl-2.0.5 3-3.4.legacy.x86_64.rpm
Apache Apache 2.0.54
-
RedHat Fedora httpd-2.0.54-10.3.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-2.0.54-10.3.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-2.0.54-10.3.x86_64.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-debuginfo-2.0.54-10.3.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-debuginfo-2.0.54-10.3.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-debuginfo-2.0.54-10.3.x86_64.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-devel-2.0.54-10.3.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-devel-2.0.54-10.3.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-devel-2.0.54-10.3.x86_64.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-manual-2.0.54-10.3.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-manual-2.0.54-10.3.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora httpd-manual-2.0.54-10.3.x86_64.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora mod_ssl-2.0.54-10.3.i386.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora mod_ssl-2.0.54-10.3.ppc.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4 -
RedHat Fedora mod_ssl-2.0.54-10.3.x86_64.rpm
Fedora Core 4
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4
References
Apache MPM Worker.C Denial Of Service Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- PK13230; 2.0.47.1: IBM HTTP Server V2.0.47 and V2.0.42 cumulative security e-fix (IBM)
- RHSA-2006:0159-8 httpd security update (RedHat)
- USN-225-1: Apache 2 vulnerability (Ubuntu)