Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
BID:19661
CVE-2006-3918 |Info
Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
| Bugtraq ID: | 19661 |
| Class: | Design Error |
| CVE: |
CVE-2006-3918 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2006 12:00AM |
| Updated: | Jun 16 2014 12:53PM |
| Credit: | Thiago Zaninotti has been credited with the discovery of this vulnerability. <br>&lt;br&gt;&amp;amp;lt;br&amp;amp;gt; |
| Vulnerable: |
VMWare ESX Server 3.0 VMWare ESX Server 2.5.4 Patch 1 VMWare ESX Server 2.5.4 VMWare ESX Server 2.5.3 Patch 4 VMWare ESX Server 2.5.3 VMWare ESX Server 2.5.2 VMWare ESX Server 2.5 VMWare ESX Server 2.1.3 Patch 2 VMWare ESX Server 2.1.3 VMWare ESX Server 2.1.2 VMWare ESX Server 2.1.1 VMWare ESX Server 2.1 VMWare ESX Server 2.0.2 Patch 2 VMWare ESX Server 2.0.2 VMWare ESX Server 2.0.1 build 6403 VMWare ESX Server 2.0.1 VMWare ESX Server 2.0 build 5257 VMWare ESX Server 2.0 VMWare ESX Server 2.5.3 Patch 2 VMWare ESX Server 2.5.2 Patch 4 VMWare ESX Server 2.1.3 Patch 1 VMWare ESX Server 2.0.2 Patch 1 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux FUJI Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE openSUSE 10.3 S.u.S.E. tomboy 10.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc RedHat Stronghold for Enterprise Linux 0 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Certificate Server 7.3 RedHat Advanced Workstation for the Itanium Processor 2.1 Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux AS 2.1 IA64 Red Hat Enterprise Linux AS 2.1 Oracle Application Server 10g 9.0.4 .3 Oracle Application Server 10g 9.0.4 .2 Oracle Application Server 10g 9.0.4 .1 Oracle Application Server 10g 9.0.4 OpenBSD OpenBSD 3.9 OpenBSD OpenBSD 3.8 IBM HTTP Server 2.0.47 .1 IBM HTTP Server 2.0.47 IBM HTTP Server 2.0.42 .2 IBM HTTP Server 2.0.42 .1 IBM HTTP Server 2.0.42 IBM HTTP Server 1.3.28 .1 IBM HTTP Server 1.3.28 IBM HTTP Server 1.3.26 .2 IBM HTTP Server 1.3.26 .1 IBM HTTP Server 1.3.26 IBM HTTP Server 1.3.19 .5 IBM HTTP Server 1.3.19 .4 IBM HTTP Server 1.3.19 .3 IBM HTTP Server 1.3.19 .2 IBM HTTP Server 1.3.19 .1 IBM HTTP Server 1.3.19 IBM HTTP Server 1.3.12 .7 IBM HTTP Server 1.3.12 .6 IBM HTTP Server 1.3.12 .5 IBM HTTP Server 1.3.12 .4 IBM HTTP Server 1.3.12 .3 IBM HTTP Server 1.3.12 .2 IBM HTTP Server 1.3.12 .1 IBM HTTP Server 1.3.12 IBM HTTP Server 6.1.0 IBM HTTP Server 6.0.2.12 IBM HTTP Server 2.2.1 IBM Hardware Management Console (HMC) for pSeries 6.0 R1.0 IBM Hardware Management Console (HMC) for iSeries 6.0 R1.0 HP OpenVMS Secure Web Server 1.2 HP OpenVMS Secure Web Server 1.1 -1 HP OpenVMS Secure Web Server 2.1-1 HP HP-UX B.11.31 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.11 F-Secure Policy Manager Server 8.11 F-Secure Policy Manager Server 8.10 F-Secure Policy Manager Server 8.00 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking Avaya Intuity LX Avaya Interactive Response 1.3 Avaya Interactive Response 1.2.1 Avaya Interactive Response 2.0 Avaya Interactive Response Avaya Integrated Management 2.1 Avaya Integrated Management Avaya CVLAN Apache Software Foundation Apache 2.0.57 Apache Software Foundation Apache 1.3.34 Apache Software Foundation Apache 2.2.1 |
| Not Vulnerable: |
IBM HTTP Server 6.0.2 .13 IBM HTTP Server 6.1.0.1 HP OpenVMS Secure Web Server 2.2 Apache Software Foundation Apache 2.2.2 Apache Software Foundation Apache 2.0.58 Apache Software Foundation Apache 1.3.35 |
Discussion
Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
Apache HTTP server is prone to a security weakness related to HTTP request headers.
An attacker may exploit this issue to steal cookie-based authentication credentials and launch other attacks.
Apache HTTP server is prone to a security weakness related to HTTP request headers.
An attacker may exploit this issue to steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
Attackers can use Flash to exploit this issue.
The following proof of concept is available.
Attackers can use Flash to exploit this issue.
The following proof of concept is available.
Solution / Fix
Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
Solution:
Updates are available. Please see the references for more information.
OpenBSD OpenBSD 3.9
F-Secure Policy Manager Server 8.11
F-Secure Policy Manager Server 8.00
Solution:
Updates are available. Please see the references for more information.
OpenBSD OpenBSD 3.9
-
OpenBSD 012_httpd2.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.9/common/012_httpd2.patch
F-Secure Policy Manager Server 8.11
-
F-Secure fspm-8.1x-hotfix-1-linux.zip
ftp://ftp.f-secure.com/support/hotfix/fspm-linux/fspm-8.1x-hotfix-1-li nux.zip -
F-Secure fspm-8.1x-hotfix-2-windows.zip
ftp://ftp.f-secure.com/support/hotfix/fspm/fspm-8.1x-hotfix-2-windows. zip
F-Secure Policy Manager Server 8.00
-
F-Secure fspm-8.00-hotfix-1-linux.zip
ftp://ftp.f-secure.com/support/hotfix/fspm-linux/fspm-8.00-hotfix-1-li nux.zip -
F-Secure fspm-8.00-hotfix-1-windows.zip
ftp://ftp.f-secure.com/support/hotfix/fspm/fspm-8.00-hotfix-1-windows. zip
References
Apache HTTP Server Arbitrary HTTP Request Headers Security Weakness
References:
References:
- Announcing Apache2 and OpenSSL Security fixes for HMC (IBM)
- Avaya: httpd security update (RHSA-2006-0619) (Avaya)
- HTTP EXPECT HEADER VALUE CAN BE ECHOED TO BROWSER UNESCAPED (IBM )
- Possible cross-site scripting exploit in Apache using Expect headers, seen in Fl (VMWare)
- RedHat Security Advisory RHSA-2006:0619-9 (RedHat)
- RedHat Security RHSA-2006:0618-4 (RedHat)
- RHSA-2006:0692-4 - apache security update for Stronghold (RedHat)
- XSS Header Injection in Oracle HTTP Server (Yasser Abouker)
- Security Advisory FSC-2010-2 (F-Secure)