Apache Non-Existent Log Directory Denial Of Service Vulnerability
BID:3790
Info
Apache Non-Existent Log Directory Denial Of Service Vulnerability
| Bugtraq ID: | 3790 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 06 2002 12:00AM |
| Updated: | Jan 06 2002 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on January 6th, 2002 by "Tozz" <[email protected]>. |
| Vulnerable: |
IBM HTTP Server 1.3.19 Apache Apache 1.3.22 Apache Apache 1.3.20 Apache Apache 1.3.19 Apache Apache 1.3.18 Apache Apache 1.3.17 Apache Apache 1.3.14 Apache Apache 1.3.12 Apache Apache 1.3.11 |
| Not Vulnerable: | |
Discussion
Apache Non-Existent Log Directory Denial Of Service Vulnerability
Under certain circumstances Apache is prone to exhibit unusual behavior, leading to a potential local denial of service attack.
When Apache is stopped, it will attempt to reload its configuration file and then proceed to shutdown. Certain problems occur if an entry for a previously existing log directory is still present in the configuration file. Apache will not be able to restart if it tries to access a previously existing log directory that has been since removed.
It should be noted that this is only really an issue if the intended setup is that unprivileged local users are able to remove directories.
This issue is believed to affect Apache running on Unix and Linux variants.
Under certain circumstances Apache is prone to exhibit unusual behavior, leading to a potential local denial of service attack.
When Apache is stopped, it will attempt to reload its configuration file and then proceed to shutdown. Certain problems occur if an entry for a previously existing log directory is still present in the configuration file. Apache will not be able to restart if it tries to access a previously existing log directory that has been since removed.
It should be noted that this is only really an issue if the intended setup is that unprivileged local users are able to remove directories.
This issue is believed to affect Apache running on Unix and Linux variants.
Exploit / POC
Apache Non-Existent Log Directory Denial Of Service Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Apache Non-Existent Log Directory Denial Of Service Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Apache Non-Existent Log Directory Denial Of Service Vulnerability
References:
References: