Apache Web Server HTTP Request Denial of Service Vulnerability
BID:2740
Info
Apache Web Server HTTP Request Denial of Service Vulnerability
| Bugtraq ID: | 2740 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 12 2001 12:00AM |
| Updated: | Apr 12 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Auriemma Luigi <[email protected]> on April 12, 2001. The fix information was reported via email by William A. Rowe, Jr. <[email protected]> on May 9, 2001. |
| Vulnerable: |
Apache Apache 1.3.19 Apache Apache 1.3.18 Apache Apache 1.3.17 Apache Apache 1.3.16 Apache Apache 1.3.15 Apache Apache 1.3.14 Apache Apache 1.3.12 |
| Not Vulnerable: |
Apache Apache 1.3.20 |
Discussion
Apache Web Server HTTP Request Denial of Service Vulnerability
It is possible for a remote user to cause a denial of service condition using various versions of Apache Web Server.
An HTTP request consisting of unusual amounts of data could cause various effects on the host. Some effects that have been reported involve the administrator receiving an error message and an idle user connection until the server is restarted by the admin. The target host could also consume all available memory, resulting in the server crashing. A restart of the server by the administrator is required in order to gain normal functionality.
It is possible for a remote user to cause a denial of service condition using various versions of Apache Web Server.
An HTTP request consisting of unusual amounts of data could cause various effects on the host. Some effects that have been reported involve the administrator receiving an error message and an idle user connection until the server is restarted by the admin. The target host could also consume all available memory, resulting in the server crashing. A restart of the server by the administrator is required in order to gain normal functionality.
Exploit / POC
Apache Web Server HTTP Request Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache Web Server HTTP Request Denial of Service Vulnerability
Solution:
Apache Group has addressed this issue in Apache Web Server 1.3.20:
Apache Apache 1.3.12
Apache Apache 1.3.14
Apache Apache 1.3.15
Apache Apache 1.3.16
Apache Apache 1.3.17
Apache Apache 1.3.18
Apache Apache 1.3.19
Solution:
Apache Group has addressed this issue in Apache Web Server 1.3.20:
Apache Apache 1.3.12
-
Apache apache_1.3.20
http://httpd.apache.org/dist/httpd/apache_1.3.20.tar.gz
Apache Apache 1.3.14
-
Apache apache_1.3.20
http://httpd.apache.org/dist/httpd/apache_1.3.20.tar.gz
Apache Apache 1.3.15
-
Apache apache_1.3.20
http://httpd.apache.org/dist/httpd/apache_1.3.20.tar.gz
Apache Apache 1.3.16
-
Apache apache_1.3.20
http://httpd.apache.org/dist/httpd/apache_1.3.20.tar.gz
Apache Apache 1.3.17
-
Apache apache_1.3.20
http://httpd.apache.org/dist/httpd/apache_1.3.20.tar.gz
Apache Apache 1.3.18
-
Apache apache_1.3.20
http://httpd.apache.org/dist/httpd/apache_1.3.20.tar.gz
Apache Apache 1.3.19
-
Apache apache_1.3.20
http://httpd.apache.org/dist/httpd/apache_1.3.20.tar.gz
References
Apache Web Server HTTP Request Denial of Service Vulnerability
References:
References:
- Apache Software Foundation Homepage (Apache Software Foundation)