RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
BID:37027
Info
RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
| Bugtraq ID: | 37027 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2009 12:00AM |
| Updated: | Nov 16 2009 03:46PM |
| Credit: | Anonymous |
| Vulnerable: |
Apache Apache 2.2.11 Apache Apache 2.2.10 Apache Apache 2.2.9 Apache Apache 2.2.8 Apache Apache 2.2.6 Apache Apache 2.2.5 Apache Apache 2.2.4 Apache Apache 2.2.3 Apache Apache 2.2.2 Apache Apache 2.2.7-dev Apache Apache 2.2.1 Apache Apache 2.2 |
| Not Vulnerable: | |
Discussion
RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
Apache Portable Runtime (APR) is prone to a remote code-execution vulnerability caused by an off-by-one error.
Successful exploits allow attackers to execute arbitrary code in the context of a vulnerable application. Failed exploit attempts may result in denial-of-service conditions.
NOTE: This BID is being retired because the issue discussed was based on misleading or incorrect information.
Apache Portable Runtime (APR) is prone to a remote code-execution vulnerability caused by an off-by-one error.
Successful exploits allow attackers to execute arbitrary code in the context of a vulnerable application. Failed exploit attempts may result in denial-of-service conditions.
NOTE: This BID is being retired because the issue discussed was based on misleading or incorrect information.
Exploit / POC
RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
NOTE: The exploit supplied by the researcher seems to be misleading and is being removed because it may be malicious. Symantec has not verified or tested the exploit.
NOTE: The exploit supplied by the researcher seems to be misleading and is being removed because it may be malicious. Symantec has not verified or tested the exploit.
Solution / Fix
RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Apache APR 'apr_uri_parse_hostinfo' Off By One Remote Code Execution Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)