Apache And Microsoft IIS Range Denial of Service Vulnerability
BID:21865
Info
Apache And Microsoft IIS Range Denial of Service Vulnerability
| Bugtraq ID: | 21865 |
| Class: | Design Error |
| CVE: |
CVE-2007-6750 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2007 12:00AM |
| Updated: | Mar 29 2017 12:03AM |
| Credit: | Michal Zalewski is credited with discovering this issue. |
| Vulnerable: |
Xerox FreeFlow Print Server (FFPS) 93.E0.21C Xerox FreeFlow Print Server (FFPS) 90.D3.06 Xerox FreeFlow Print Server (FFPS) 82.D2.24 Xerox FreeFlow Print Server (FFPS) 82.D1.44 Xerox FreeFlow Print Server (FFPS) 82.C5.24 Xerox FreeFlow Print Server (FFPS) 81.D0.73 Xerox FreeFlow Print Server (FFPS) 81.C3.31 Xerox FreeFlow Print Server (FFPS) 73.D4.31B Xerox FreeFlow Print Server (FFPS) 73.D4.31 Xerox FreeFlow Print Server (FFPS) 73.D2.33 SuSE SUSE Linux Enterprise Server for VMware 11 SP1 SuSE SUSE Linux Enterprise Server 11 SP1 SuSE SUSE Linux Enterprise Server 10 SP4 SuSE SUSE Linux Enterprise SDK 11 SP1 SuSE SUSE Linux Enterprise SDK 10 SP4 Oracle Solaris 10 Microsoft IIS 6.0 Microsoft IIS 5.1 Microsoft IIS 5.0 Microsoft IIS 4.0 alpha Microsoft IIS 4.0 Microsoft IIS 3.0 alpha Microsoft IIS 3.0 Microsoft IIS 2.0 Microsoft IIS 1.0 IBM Storwize V7000 Unified 1.4.3 3 IBM Storwize V7000 Unified 1.4.3 2 IBM Storwize V7000 Unified 1.4 1 IBM Storwize V7000 Unified 1.4 0 IBM Storwize V7000 Unified 1.3.2 3 IBM Storwize V7000 Unified 1.3.2 1 IBM Storwize V7000 Unified 1.3.2 0 IBM Storwize V7000 Unified 1.5.0.1 IBM Storwize V7000 Unified 1.5.0.0 IBM Storwize V7000 Unified 1.4.3.0 IBM Storwize V7000 Unified 1.4.2.1 IBM Storwize V7000 Unified 1.4.2.0 IBM Storwize V7000 Unified 1.4.1.1 IBM Storwize V7000 Unified 1.4.1.0 IBM Storwize V7000 Unified 1.3.1.0 IBM Storwize V7000 Unified 1.3.0.5 IBM Storwize V7000 Unified 1.3.0.0 IBM Security Network Intrusion Prevention System GX7800 4.6.2 IBM Security Network Intrusion Prevention System GX7800 4.6.1 IBM Security Network Intrusion Prevention System GX7800 4.6 IBM Security Network Intrusion Prevention System GX7800 4.5 IBM Security Network Intrusion Prevention System GX7800 4.4 IBM Security Network Intrusion Prevention System GX7800 4.3 IBM Security Network Intrusion Prevention System GX7412-10 4.6.2 IBM Security Network Intrusion Prevention System GX7412-10 4.6.1 IBM Security Network Intrusion Prevention System GX7412-10 4.6 IBM Security Network Intrusion Prevention System GX7412-10 4.5 IBM Security Network Intrusion Prevention System GX7412-10 4.4 IBM Security Network Intrusion Prevention System GX7412-10 4.3 IBM Security Network Intrusion Prevention System GX7412-05 4.6.2 IBM Security Network Intrusion Prevention System GX7412-05 4.6.1 IBM Security Network Intrusion Prevention System GX7412-05 4.6 IBM Security Network Intrusion Prevention System GX7412-05 4.5 IBM Security Network Intrusion Prevention System GX7412-05 4.4 IBM Security Network Intrusion Prevention System GX7412-05 4.3 IBM Security Network Intrusion Prevention System GX7412 4.6.2 IBM Security Network Intrusion Prevention System GX7412 4.6.1 IBM Security Network Intrusion Prevention System GX7412 4.6 IBM Security Network Intrusion Prevention System GX7412 4.5 IBM Security Network Intrusion Prevention System GX7412 4.4 IBM Security Network Intrusion Prevention System GX7412 4.3 IBM Security Network Intrusion Prevention System GX6116 4.6.2 IBM Security Network Intrusion Prevention System GX6116 4.6.1 IBM Security Network Intrusion Prevention System GX6116 4.6 IBM Security Network Intrusion Prevention System GX6116 4.5 IBM Security Network Intrusion Prevention System GX6116 4.4 IBM Security Network Intrusion Prevention System GX6116 4.3 IBM Security Network Intrusion Prevention System GX5208-v2 4.6.2 IBM Security Network Intrusion Prevention System GX5208-v2 4.6.1 IBM Security Network Intrusion Prevention System GX5208-v2 4.6 IBM Security Network Intrusion Prevention System GX5208-v2 4.5 IBM Security Network Intrusion Prevention System GX5208-v2 4.4 IBM Security Network Intrusion Prevention System GX5208-v2 4.3 IBM Security Network Intrusion Prevention System GX5208 4.6.2 IBM Security Network Intrusion Prevention System GX5208 4.6.1 IBM Security Network Intrusion Prevention System GX5208 4.6 IBM Security Network Intrusion Prevention System GX5208 4.5 IBM Security Network Intrusion Prevention System GX5208 4.4 IBM Security Network Intrusion Prevention System GX5208 4.3 IBM Security Network Intrusion Prevention System GX5108-v2 4.6.2 IBM Security Network Intrusion Prevention System GX5108-v2 4.6.1 IBM Security Network Intrusion Prevention System GX5108-v2 4.6 IBM Security Network Intrusion Prevention System GX5108-v2 4.5 IBM Security Network Intrusion Prevention System GX5108-v2 4.4 IBM Security Network Intrusion Prevention System GX5108-v2 4.3 IBM Security Network Intrusion Prevention System GX5108 4.6.2 IBM Security Network Intrusion Prevention System GX5108 4.6.1 IBM Security Network Intrusion Prevention System GX5108 4.6 IBM Security Network Intrusion Prevention System GX5108 4.5 IBM Security Network Intrusion Prevention System GX5108 4.4 IBM Security Network Intrusion Prevention System GX5108 4.3 IBM Security Network Intrusion Prevention System GX5008-v2 4.6.2 IBM Security Network Intrusion Prevention System GX5008-v2 4.6.1 IBM Security Network Intrusion Prevention System GX5008-v2 4.6 IBM Security Network Intrusion Prevention System GX5008-v2 4.5 IBM Security Network Intrusion Prevention System GX5008-v2 4.4 IBM Security Network Intrusion Prevention System GX5008-v2 4.3 IBM Security Network Intrusion Prevention System GX5008 4.6.2 IBM Security Network Intrusion Prevention System GX5008 4.6.1 IBM Security Network Intrusion Prevention System GX5008 4.6 IBM Security Network Intrusion Prevention System GX5008 4.5 IBM Security Network Intrusion Prevention System GX5008 4.4 IBM Security Network Intrusion Prevention System GX5008 4.3 IBM Security Network Intrusion Prevention System GX4004-v2 4.6.2 IBM Security Network Intrusion Prevention System GX4004-v2 4.6.1 IBM Security Network Intrusion Prevention System GX4004-v2 4.6 IBM Security Network Intrusion Prevention System GX4004-v2 4.5 IBM Security Network Intrusion Prevention System GX4004-v2 4.4 IBM Security Network Intrusion Prevention System GX4004-v2 4.3 IBM Security Network Intrusion Prevention System GX4004 4.6.2 IBM Security Network Intrusion Prevention System GX4004 4.6.1 IBM Security Network Intrusion Prevention System GX4004 4.6 IBM Security Network Intrusion Prevention System GX4004 4.5 IBM Security Network Intrusion Prevention System GX4004 4.4 IBM Security Network Intrusion Prevention System GX4004 4.3 IBM Security Network Intrusion Prevention System GX4002 4.6.2 IBM Security Network Intrusion Prevention System GX4002 4.6.1 IBM Security Network Intrusion Prevention System GX4002 4.6 IBM Security Network Intrusion Prevention System GX4002 4.5 IBM Security Network Intrusion Prevention System GX4002 4.4 IBM Security Network Intrusion Prevention System GX4002 4.3 IBM Security Network Intrusion Prevention System GX3002 4.6.2 IBM Security Network Intrusion Prevention System GX3002 4.6.1 IBM Security Network Intrusion Prevention System GX3002 4.6 IBM Security Network Intrusion Prevention System GX3002 4.5 IBM Security Network Intrusion Prevention System GX3002 4.4 IBM Security Network Intrusion Prevention System GX3002 4.3 IBM Security Network Intrusion Prevention System GV200 4.6.2 IBM Security Network Intrusion Prevention System GV200 4.6.1 IBM Security Network Intrusion Prevention System GV200 4.6 IBM Security Network Intrusion Prevention System GV200 4.5 IBM Security Network Intrusion Prevention System GV200 4.4 IBM Security Network Intrusion Prevention System GV200 4.3 IBM Security Network Intrusion Prevention System GV1000 4.6.2 IBM Security Network Intrusion Prevention System GV1000 4.6.1 IBM Security Network Intrusion Prevention System GV1000 4.6 IBM Security Network Intrusion Prevention System GV1000 4.5 IBM Security Network Intrusion Prevention System GV1000 4.4 IBM Security Network Intrusion Prevention System GV1000 4.3 IBM Scale Out Network Attached Storage 1.3.2 1-21 IBM Scale Out Network Attached Storage 1.3.2 1-20 IBM Scale Out Network Attached Storage 1.3.2 IBM Scale Out Network Attached Storage 1.3.1 IBM Scale Out Network Attached Storage 1.4.3.3 IBM Scale Out Network Attached Storage 1.4.3.2 IBM Scale Out Network Attached Storage 1.4.3.1 IBM Scale Out Network Attached Storage 1.4.3.0 IBM Scale Out Network Attached Storage 1.4.2.1 IBM Scale Out Network Attached Storage 1.4.2.0 IBM Scale Out Network Attached Storage 1.4.1.0 IBM Scale Out Network Attached Storage 1.3.2.3 IBM Scale Out Network Attached Storage 1.3.2.2 IBM Scale Out Network Attached Storage 1.3.0.5 IBM Scale Out Network Attached Storage 1.3.0.4 IBM Scale Out Network Attached Storage 1.3.0.0 HP Version Control Repository Manager 7.4.1 HP Version Control Repository Manager 7.4 HP Version Control Repository Manager 7.3.4 HP Version Control Repository Manager 7.3.1 HP Version Control Repository Manager 7.3 HP Version Control Repository Manager 7.2.2 HP Version Control Repository Manager 7.2.1 HP Version Control Repository Manager 7.2 HP Version Control Repository Manager 7.5.0 HP Version Control Repository Manager 7.3.3 HP Version Control Repository Manager 7.3.2 HP Systems Insight Manager 7.1.1 HP Systems Insight Manager 7.5.0 HP Systems Insight Manager 7.4 HP Systems Insight Manager 7.3.2 HP Systems Insight Manager 7.3.1 HP Systems Insight Manager 7.3 HP Systems Insight Manager 7.2.2 HP Systems Insight Manager 7.2.1 HP Systems Insight Manager 7.2 HP Systems Insight Manager 7.0 HP System Management Homepage 7.5.4 HP System Management Homepage 7.5 HP System Management Homepage 7.4.1 HP System Management Homepage 7.3.2 HP System Management Homepage 7.2.3 HP System Management Homepage 7.2.2 HP System Management Homepage 7.2.1 HP System Management Homepage 7.2 HP System Management Homepage 7.1.2 HP System Management Homepage 7.1.1 HP System Management Homepage 7.4 HP System Management Homepage 7.3.3.1 HP System Management Homepage 7.3.1 HP System Management Homepage 7.3 HP System Management Homepage 7.2.4.1 HP System Management Homepage 7.1 HP System Management Homepage 7.0 HP Server Migration Pack 7.5 HP Insight Control server provisioning 7.4.1 HP Insight Control server provisioning 7.5.0 HP Insight Control server provisioning 7.4.0 HP Insight Control 7.5 HP Insight Control 7.4 HP Insight Control 7.3 HP Insight Control 7.2 HP HP-UX B.11.31 Gentoo Linux Apple macOS Server 5.2 Apple macOS 10.12.4 Apache Apache 2.2.3 Apache Apache 2.2.2 Apache Apache 2.2 Apache Apache 2.1.8 Apache Apache 2.1.7 Apache Apache 2.1.6 Apache Apache 2.1.5 Apache Apache 2.1.4 Apache Apache 2.1.3 Apache Apache 2.1.2 Apache Apache 2.1.1 Apache Apache 2.1 Apache Apache 2.0.59 Apache Apache 2.0.58 Apache Apache 2.0.56 -dev Apache Apache 2.0.55 Apache Apache 2.0.54 Apache Apache 2.0.53 Apache Apache 2.0.52 Apache Apache 2.0.51 Apache Apache 2.0.50 Apache Apache 2.0.49 Apache Apache 2.0.48 Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.34 -BETA Apache Apache 2.0.32 -BETA Apache Apache 2.0.32 Apache Apache 2.0.28 -BETA Apache Apache 2.0.28 Beta Apache Apache 2.0.28 Apache Apache 2.0 a9 Apache Apache 2.0 Apache Apache 1.3.37 Apache Apache 1.3.36 Apache Apache 1.3.35 -dev Apache Apache 1.3.34 Apache Apache 1.3.33 Apache Apache 1.3.32 Apache Apache 1.3.31 Apache Apache 1.3.29 Apache Apache 1.3.28 Apache Apache 1.3.27 Apache Apache 1.3.26 Apache Apache 1.3.25 Apache Apache 1.3.24 Apache Apache 1.3.23 Apache Apache 1.3.22 Apache Apache 1.3.20 Apache Apache 1.3.19 Apache Apache 1.3.18 Apache Apache 1.3.17 Apache Apache 1.3.16 Apache Apache 1.3.15 Apache Apache 1.3.14 Mac Apache Apache 1.3.14 Apache Apache 1.3.13 Apache Apache 1.3.12 Apache Apache 1.3.11 Apache Apache 1.3.9 Apache Apache 1.3.7 -dev Apache Apache 1.3.6 Apache Apache 1.3.4 Apache Apache 1.3.3 Apache Apache 1.3.1 Apache Apache 1.3 Apache Apache 1.2.5 Apache Apache 1.2 Apache Apache 1.1.1 Apache Apache 1.1 Apache Apache 1.0.5 Apache Apache 1.0.3 Apache Apache 1.0.2 Apache Apache 1.0 Apache Apache 0.8.14 Apache Apache 0.8.11 |
| Not Vulnerable: |
HP Version Control Repository Manager 7.5.1 HP Systems Insight Manager 7.5.1 HP System Management Homepage 7.5.5 HP Server Migration Pack 7.5.1 HP Insight Control server provisioning 7.5.1 HP Insight Control 7.5.1 Apple macOS Server 5.3 |
Discussion
Apache And Microsoft IIS Range Denial of Service Vulnerability
Apache and Microsoft IIS are prone to a denial-of-service vulnerability.
A remote attacker may exploit this issue to cause denial-of-service conditions.
Apache and Microsoft IIS are prone to a denial-of-service vulnerability.
A remote attacker may exploit this issue to cause denial-of-service conditions.
Exploit / POC
Apache And Microsoft IIS Range Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache And Microsoft IIS Range Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache And Microsoft IIS Range Denial of Service Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- CVE-2007-6750 Resource Management Errors vulnerability in Apache (Oracle)
- HPSBUX02866 SSRT101139 rev.1 - HP-UX Running Apache, Remote Denial of Service (D (HP)
- Microsoft IIS Homepage (Microsoft)
- Xerox Security Bulletin XRX14-004 (Xerox)
- a cheesy Apache / IIS DoS vuln (+a question) (Michal Zalewski)
- HPSBMU03612 rev.1 - HPE Insight Control on Windows and Linux, Multiple Remote Vu (HP)
- Security Bulletin: Denial of service for accessing data using HTTP protocol on I (IBM)
- Security Bulletin: Denial of service for accessing data using HTTP protocol on I (IBM)
- Security Bulletin: IBM Security Network Intrusion Prevention System is affected (IBM)