Apache HTTP Server Mod_Cache Denial of Service Vulnerability
BID:24649
Info
Apache HTTP Server Mod_Cache Denial of Service Vulnerability
| Bugtraq ID: | 24649 |
| Class: | Design Error |
| CVE: |
CVE-2007-1863 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2007 12:00AM |
| Updated: | Aug 05 2010 09:15PM |
| Credit: | Niklas Edmundsson is credited with discovering this vulnerability. |
| Vulnerable: |
VMWare Workstation 6.5.2 VMWare Workstation 6.5.1 VMWare Player 2.5.2 VMWare Player 2.5.1 VMWare ACE 2.5.2 VMWare ACE 2.5.1 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux FUJI 0 Turbolinux Appliance Server 2.0 Trustix Secure Linux 3.0.5 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Operating System Enterprise Server 2.0 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SGI ProPack 3.0 SP6 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.1 rPath rPath Linux 1 Redhat Fedora Core7 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Certificate Server 7.3 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 IBM HTTP Server 6.0.2 .13 IBM HTTP Server 6.1.0.13 IBM HTTP Server 6.1.0.1 IBM HTTP Server 6.1.0 IBM HTTP Server 6.0.2.23 IBM HTTP Server 6.0.2.12 HP HP-UX B.11.31 HP HP-UX B.11.23 HP HP-UX B.11.11 Gentoo Linux Fujitsu INTERSTAGE Studio Standard-J Edition 9.0 Fujitsu INTERSTAGE Studio Standard-J Edition 8.0.1 Fujitsu INTERSTAGE Studio Enterprise Edition 9.0 Fujitsu INTERSTAGE Studio Enterprise Edition 8.0.1 Fujitsu INTERSTAGE Job Workload Server 8.1 Fujitsu INTERSTAGE Business Application Server Enterprise 8.0.0 Fujitsu INTERSTAGE Apworks Standard-J Edition 8.0 Fujitsu INTERSTAGE Apworks Modelers-J Edition 7.0 Fujitsu INTERSTAGE Apworks Modelers-J Edition 6.0A Fujitsu INTERSTAGE Apworks Modelers-J Edition 6.0 Fujitsu INTERSTAGE Apworks Enterprise Edition 8.0 Fujitsu iNTERSTAGE Application Server Web-J Edition 5.0 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 A Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 Fujitsu INTERSTAGE Application Server Standard-J Edition 8.0.2 Fujitsu INTERSTAGE Application Server Standard-J Edition 8.0.1 Fujitsu INTERSTAGE Application Server Standard-J Edition 8.0 Fujitsu iNTERSTAGE Application Server Standard Edition 5.0 Fujitsu INTERSTAGE Application Server Plus Developer 5.0.1 Fujitsu INTERSTAGE Application Server Plus Developer 7.0 Fujitsu INTERSTAGE Application Server Plus Developer 6.0 Fujitsu Interstage Application Server Plus 7.0.1 Fujitsu Interstage Application Server Plus 5.0.1 Fujitsu Interstage Application Server Plus 7.0 Fujitsu Interstage Application Server Plus 6.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0 A Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 8.0.2 Fujitsu INTERSTAGE Application Server Enterprise Edition 8.0.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 8.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 7.0.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 7.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 6.0A Fujitsu INTERSTAGE Application Server Enterprise Edition 6.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 5.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking Avaya EMMC 1.021 Avaya EMMC 1.017 Avaya EMMC 0 Avaya Communication Manager 2.0.1 Avaya Communication Manager 2.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 3.1.3 Avaya Aura Application Enablement Services 4.0 Avaya Aura Application Enablement Services 3.1 Avaya Aura Application Enablement Services 3.0 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.5 Apache Apache 2.2.4 Apache Apache 2.2.3 Apache Apache 2.2 Apache Apache 2.1.8 Apache Apache 2.1.7 Apache Apache 2.1.6 Apache Apache 2.1.5 Apache Apache 2.1.4 Apache Apache 2.1.3 Apache Apache 2.1.2 Apache Apache 2.1.1 Apache Apache 2.1 Apache Apache 2.0.59 Apache Apache 2.0.58 Apache Apache 2.0.56 -dev Apache Apache 2.0.55 Apache Apache 2.0.54 Apache Apache 2.0.53 Apache Apache 2.0.52 Apache Apache 2.0.51 Apache Apache 2.0.50 Apache Apache 2.0.49 Apache Apache 2.0.48 Apache Apache 2.0.47 Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.32 Apache Apache 2.0.28 Beta Apache Apache 2.0.28 Apache Apache 2.0 a9 Apache Apache 2.0 Apache Apache 1.3.37 Apache Apache 1.3.36 Apache Apache 1.3.35 -dev Apache Apache 1.3.34 Apache Apache 1.3.33 Apache Apache 1.3.32 Apache Apache 1.3.31 Apache Apache 1.3.29 Apache Apache 1.3.28 Apache Apache 1.3.27 Apache Apache 1.3.26 Apache Apache 1.3.25 Apache Apache 1.3.24 Apache Apache 1.3.23 Apache Apache 1.3.22 Apache Apache 1.3.20 Apache Apache 1.3.19 Apache Apache 1.3.18 Apache Apache 1.3.17 Apache Apache 1.3.14 Apache Apache 1.3.12 Apache Apache 1.3.11 Apache Apache 1.3.9 Apache Apache 1.3.7 -dev Apache Apache 1.3.6 Apache Apache 1.3.4 Apache Apache 1.3.3 Apache Apache 1.3.1 Apache Apache 1.3 Apache Apache 1.2.5 Apache Apache 1.2 Apache Apache 1.1.1 Apache Apache 1.1 Apache Apache 1.0.5 Apache Apache 1.0.3 Apache Apache 1.0.2 Apache Apache 1.0 |
| Not Vulnerable: |
Apache Apache 2.2.5-dev Apache Apache 2.0.60-dev |
Discussion
Apache HTTP Server Mod_Cache Denial of Service Vulnerability
The Apache mod_cache module is prone to a denial-of-service vulnerability.
A remote attacker may be able to exploit this issue to crash the child process. This could lead to denial-of-service conditions if the server is using a multithreaded Multi-Processing Module (MPM).
The Apache mod_cache module is prone to a denial-of-service vulnerability.
A remote attacker may be able to exploit this issue to crash the child process. This could lead to denial-of-service conditions if the server is using a multithreaded Multi-Processing Module (MPM).
Exploit / POC
Apache HTTP Server Mod_Cache Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache HTTP Server Mod_Cache Denial of Service Vulnerability
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
Apple Mac OS X 10.4.11
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.4.11
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
Apple Mac OS X 10.5.2
-
Apple Security Update 2008-003 (Intel)
http://www.apple.com/support/downloads/securityupdate2008003intel.html -
Apple Security Update 2008-003 (PPC)
http://www.apple.com/support/downloads/securityupdate2008003ppc.html
Apple Mac OS X Server 10.5.2
-
Apple Security Update 2008-003 Server (PPC)
http://www.apple.com/support/downloads/securityupdate2008003serverppc. html -
Apple Security Update 2008-003 Server (Universal)
http://www.apple.com/support/downloads/securityupdate2008003serveruniv ersal.html
References
Apache HTTP Server Mod_Cache Denial of Service Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Apache httpd 1.3 vulnerabilities (Apache)
- Apache httpd 2.0 vulnerabilities (Apache Software Foundation)
- Apache httpd 2.2 vulnerabilities (Apache Software Foundation)
- Bugzilla Bug 244658: CVE-2007-1863 httpd mod_cache segfault (Red Hat)
- HPSBUX02262 SSRT071447 rev. 1 (Hewlett-Packard)
- TSLSA-2007-0026 - multi (Trustix)
- ASA-2007-327 httpd security update (RHSA-2007-0533 and RHSA-2007-0534) (Avaya)
- Avaya Security Advisory ASA-2007-353 (Avaya)
- Cross site scripting (XSS) and denial of service (DoS) vulnerabilities in Inters (Fujitsu)
- PK49355: CVE-2007-1863 MOD_CACHE CRASH WITH MALICIOUS REQUEST (IBM)
- PK52702: Z/OS IBM HTTP SERVER FOR WEBSPHERE (POWERED BY APACHE) FIX PACK 6.1.0.1 (IBM)
- RHSA-2007:0533-3 httpd security update (Red Hat)
- RHSA-2007:0534-4 httpd security update (Red Hat)
- RHSA-2007:0556-2 httpd security update (Red Hat)