Apache 'mod_isapi' Memory Corruption Vulnerability
BID:38494
CVE-2010-425 |Info
Apache 'mod_isapi' Memory Corruption Vulnerability
| Bugtraq ID: | 38494 |
| Class: | Unknown |
| CVE: |
CVE-2010-0425 CVE-2010-0434 CVE-2010-0434 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 02 2010 12:00AM |
| Updated: | Apr 13 2015 09:26PM |
| Credit: | Brett Gervasoni |
| Vulnerable: |
Sun Solaris 10_x86 Sun Solaris 10_sparc Sun OpenSolaris build snv_99 Sun OpenSolaris build snv_98 Sun OpenSolaris build snv_96 Sun OpenSolaris build snv_95 Sun OpenSolaris build snv_94 Sun OpenSolaris build snv_93 Sun OpenSolaris build snv_92 Sun OpenSolaris build snv_91 Sun OpenSolaris build snv_90 Sun OpenSolaris build snv_89 Sun OpenSolaris build snv_88 Sun OpenSolaris build snv_87 Sun OpenSolaris build snv_86 Sun OpenSolaris build snv_85 Sun OpenSolaris build snv_84 Sun OpenSolaris build snv_83 Sun OpenSolaris build snv_82 Sun OpenSolaris build snv_81 Sun OpenSolaris build snv_80 Sun OpenSolaris build snv_78 Sun OpenSolaris build snv_77 Sun OpenSolaris build snv_76 Sun OpenSolaris build snv_74 Sun OpenSolaris build snv_71 Sun OpenSolaris build snv_68 Sun OpenSolaris build snv_67 Sun OpenSolaris build snv_64 Sun OpenSolaris build snv_61 Sun OpenSolaris build snv_59 Sun OpenSolaris build snv_58 Sun OpenSolaris build snv_57 Sun OpenSolaris build snv_56 Sun OpenSolaris build snv_54 Sun OpenSolaris build snv_51 Sun OpenSolaris build snv_50 Sun OpenSolaris build snv_49 Sun OpenSolaris build snv_48 Sun OpenSolaris build snv_47 Sun OpenSolaris build snv_45 Sun OpenSolaris build snv_41 Sun OpenSolaris build snv_39 Sun OpenSolaris build snv_38 Sun OpenSolaris build snv_37 Sun OpenSolaris build snv_36 Sun OpenSolaris build snv_35 Sun OpenSolaris build snv_29 Sun OpenSolaris build snv_28 Sun OpenSolaris build snv_22 Sun OpenSolaris build snv_19 Sun OpenSolaris build snv_13 Sun OpenSolaris build snv_111a Sun OpenSolaris build snv_111 Sun OpenSolaris build snv_110 Sun OpenSolaris build snv_109 Sun OpenSolaris build snv_108 Sun OpenSolaris build snv_107 Sun OpenSolaris build snv_106 Sun OpenSolaris build snv_105 Sun OpenSolaris build snv_104 Sun OpenSolaris build snv_103 Sun OpenSolaris build snv_102 Sun OpenSolaris build snv_101a Sun OpenSolaris build snv_101 Sun OpenSolaris build snv_100 Sun OpenSolaris build snv_02 Sun OpenSolaris build snv_01 Sun OpenSolaris Build Snv 111B Sun OpenSolaris 0 Slackware Linux x86_64 -current Slackware Linux 13.0 x86_64 Slackware Linux 13.0 Slackware Linux 12.2 Slackware Linux 12.1 Slackware Linux 12.0 Slackware Linux -current rPath rPath Linux 1 rPath Appliance Platform Linux Service 1 RedHat Certificate Server 7.3 Red Hat JBoss Enterprise Web Server for RHEL 5 Server 1.0 Red Hat JBoss Enterprise Web Server for RHEL 4 ES 1.0 Red Hat JBoss Enterprise Web Server for RHEL 4 AS 1.0 Kolab Kolab Groupware Server 2.2.3 Kolab Kolab Groupware Server 2.2.2 Kolab Kolab Groupware Server 2.2 Kolab Kolab Groupware Server 2.2-rc3 Kolab Kolab Groupware Server 2.2-rc1 Kolab Kolab Groupware Server 2.2 beta3 Kolab Kolab Groupware Server 2.2 beta1 Kolab Kolab Groupware Server 2.2 -rc2 IBM Websphere Application Server 7.0 3 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .25 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 6.1 IBM Websphere Application Server 7.0.0.7 IBM Websphere Application Server 7.0.0.5 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0 IBM Websphere Application Server 6.1.0.29 IBM Websphere Application Server 6.1.0.27 IBM HTTP Server 2.0.47 .1 IBM HTTP Server 2.0.47 IBM HTTP Server 6.1.0 Gentoo Linux Fujitsu INTERSTAGE Studio Standard-J Edition 9.2 Fujitsu INTERSTAGE Studio Standard-J Edition 9.1 Fujitsu INTERSTAGE Studio Standard-J Edition 9.0 Fujitsu INTERSTAGE Studio Standard-J Edition 9.1.0 B Fujitsu INTERSTAGE Studio Enterprise Edition 9.2 Fujitsu INTERSTAGE Studio Enterprise Edition 9.1 Fujitsu INTERSTAGE Studio Enterprise Edition 9.0 Fujitsu INTERSTAGE Studio Enterprise Edition 9.1.0 B Fujitsu INTERSTAGE Application Server Standard-J Edition 9.2 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.1 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 B Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 A Fujitsu INTERSTAGE Application Server Standard-J Edition 9.0 Fujitsu INTERSTAGE Application Server Standard-J Edition 9.1.0B Fujitsu INTERSTAGE Application Server Enterprise Edition 9.2 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.1 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0 A Fujitsu INTERSTAGE Application Server Enterprise Edition 9.0 Fujitsu INTERSTAGE Application Server Enterprise Edition 9.1.0B Blue Coat Systems Director 5.2.2 .5 Blue Coat Systems Director 4.2.2 .4 Blue Coat Systems Director 5.5 Blue Coat Systems Director 5.4 Blue Coat Systems Director 0 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 Avaya Voice Portal 4.1 SP2 Avaya Voice Portal 4.1 SP1 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Message Networking 5.2 Avaya Message Networking 3.1 Avaya Meeting Exchange 5.2 SP1 Avaya Meeting Exchange 5.2 Avaya Meeting Exchange 5.1 SP1 Avaya Meeting Exchange 5.1 Avaya Meeting Exchange 5.0 SP2 Avaya Meeting Exchange 5.0 SP1 Avaya Meeting Exchange 5.0 Avaya Intuity AUDIX LX 2.0 SP2 Avaya Intuity AUDIX LX 2.0 SP1 Avaya Intuity AUDIX LX 2.0 Avaya Communication Manager 5.1.2 Avaya Communication Manager 4.0.3 SP1 Avaya Communication Manager 5.2 Avaya Communication Manager 5.1 Avaya Communication Manager 5.0 SP3 Avaya Communication Manager 5.0 Avaya Communication Manager 4.0 Avaya Aura SIP Enablement Services 5.2 Avaya Aura SIP Enablement Services 5.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura SIP Enablement Services 4.0 Avaya Aura SIP Enablement Services 3.1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Application Enablement Services 4.2.2 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 4.0.1 Avaya Aura Application Enablement Services 5.2 Avaya Aura Application Enablement Services 4.2 Avaya Aura Application Enablement Services 4.1 Avaya Aura Application Enablement Services 4.0 Apache Software Foundation Apache 2.2.14 Apache Software Foundation Apache 2.2.13 Apache Software Foundation Apache 2.2.12 Apache Software Foundation Apache 2.2.11 Apache Software Foundation Apache 2.2.10 Apache Software Foundation Apache 2.2.9 Apache Software Foundation Apache 2.2.8 Apache Software Foundation Apache 2.2.6 Apache Software Foundation Apache 2.2.5 Apache Software Foundation Apache 2.2.4 Apache Software Foundation Apache 2.2.3 Apache Software Foundation Apache 2.2.2 Apache Software Foundation Apache 2.2 Apache Software Foundation Apache 2.0.63 Apache Software Foundation Apache 2.0.59 Apache Software Foundation Apache 2.0.58 Apache Software Foundation Apache 2.0.57 Apache Software Foundation Apache 2.0.56 -dev Apache Software Foundation Apache 2.0.55 Apache Software Foundation Apache 2.0.54 Apache Software Foundation Apache 2.0.53 Apache Software Foundation Apache 2.0.52 Apache Software Foundation Apache 2.0.51 Apache Software Foundation Apache 2.0.50 Apache Software Foundation Apache 2.0.49 Apache Software Foundation Apache 2.0.48 Apache Software Foundation Apache 2.0.47 Apache Software Foundation Apache 2.0.46 Apache Software Foundation Apache 2.0.45 Apache Software Foundation Apache 2.0.44 Apache Software Foundation Apache 2.0.43 Apache Software Foundation Apache 2.0.42 Apache Software Foundation Apache 2.0.41 Apache Software Foundation Apache 2.0.40 Apache Software Foundation Apache 2.0.39 Apache Software Foundation Apache 2.0.38 Apache Software Foundation Apache 2.0.37 Apache Software Foundation Apache 2.2.7-dev Apache Software Foundation Apache 2.2.6-dev Apache Software Foundation Apache 2.2.5-dev Apache Software Foundation Apache 2.2.1 Apache Software Foundation Apache 2.2 Apache Software Foundation Apache 2.0.62-dev Apache Software Foundation Apache 2.0.61-dev Apache Software Foundation Apache 2.0.60-dev |
| Not Vulnerable: |
Kolab Kolab Groupware Server 2.2.4 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.1.0.31 Blue Coat Systems Director 5.5.2.3 Apache Software Foundation Apache 2.2.15 Apache Software Foundation Apache 2.2.15-dev Apache Software Foundation Apache 2.0.64-dev |
Discussion
Apache 'mod_isapi' Memory Corruption Vulnerability
Apache is prone to a memory-corruption vulnerability.
Attackers can leverage this vulnerability to execute arbitrary code with SYSTEM privileges; failed attacks may result in denial-of-service conditions.
Apache versions prior to 2.2.15 are affected.
Apache is prone to a memory-corruption vulnerability.
Attackers can leverage this vulnerability to execute arbitrary code with SYSTEM privileges; failed attacks may result in denial-of-service conditions.
Apache versions prior to 2.2.15 are affected.
Exploit / POC
Apache 'mod_isapi' Memory Corruption Vulnerability
The following exploit and proof-of-concept are available:
The following exploit and proof-of-concept are available:
Solution / Fix
Apache 'mod_isapi' Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
Kolab Kolab Groupware Server 2.2 beta3
Slackware Linux x86_64 -current
Kolab Kolab Groupware Server 2.2-rc3
Kolab Kolab Groupware Server 2.2
Solution:
Updates are available. Please see the references for more information.
Slackware Linux 12.2
-
Slackware httpd-2.2.15-i486-1_slack12.2.tgz
ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/ httpd-2.2.15-i486-1_slack12.2.tgz
Kolab Kolab Groupware Server 2.2 beta3
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
Slackware Linux x86_64 -current
-
Slackware httpd-2.2.15-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/ n/httpd-2.2.15-x86_64-1.txz
Kolab Kolab Groupware Server 2.2-rc3
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
Kolab Kolab Groupware Server 2.2
-
Kolab kolab-server-2.2.4
http://files.kolab.org/server/release/kolab-server-2.2.4/
References
Apache 'mod_isapi' Memory Corruption Vulnerability
References:
References:
- Apache httpd 2.2 vulnerabilities (Apache Software Foundation)
- Apache Homepage (Apache Software Foundation)
- Apache httpd 2.0 vulnerabilities (Apache Software Foundation)
- Buffer overflow related to setting RequestHeader (Apache Software Foundation)
- Kolab Server 2.2.4 Final Release (Kolab)
- Multiple Vulnerabilities in the Apache 2 HTTP Server Prior to 2.2.16 (chandan)
- Multiple Vulnerabilities in the Apache 2 HTTP Server Prior to 2.2.16 (Oracle)
- PM08939: CVE-2010-0434 / CVE-2010-0408 (IBM)
- PM10658: IBM HTTP SERVER 2.0.47 CUMULATIVE INTERIM FIX (IBM)
- PM12247: SHIP APAR FIXES FOR H28W610 FIX PACK 6.1.0 (IBM)
- PM15829: SHIP APAR FIXES FOR H28W700 FIX PACK 7.0.0.11. (IBM)
- Revision 917870 (Apache Software Foundation)
- Sense of Security - Security Advisory - SOS-10-002 - Apache 2.2.14 mod_isapi Dan (Sense of Security)
- ASA-2010-110 httpd security and enhancement update (RHSA-2010-0168) (Avaya)
- Avaya Security Advisory ASA-2010-109 (Avaya)
- Oracle Critical Patch Update Advisory - July 2013 (Oracle)
- PM09447: CVE-2010-0425 MOD_ISAPI VULNERABILITY (IBM)
- September 13, 2011 - Director multiple Apache vulnerabilities (Blue Coat)
- Three Security Vulnerabilities in Interstage HTTP Server (CVE-2008-2364/ CVE-201 (Fujitsu)
- Vulnerability Note VU#280613 Apache mod_isapi module library unload results in o (US-CERT)