Apache HTTP Server Multiple Denial of Service Vulnerabilities
BID:66303
Info
Apache HTTP Server Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 66303 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2013-6438 CVE-2014-0098 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2014 12:00AM |
| Updated: | Jul 15 2015 12:34AM |
| Credit: | Rainer M Canavan, Ning Zhang, and Amin Tora of Neustar. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 10 SP3 LTSS SuSE openSUSE 11.4 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Puppet Labs Puppet Enterprise 2.5.1 Puppet Labs Puppet Enterprise 2.0.3 Puppet Labs Puppet Enterprise 2.0.2 Puppet Labs Puppet Enterprise 2.6 Puppet Labs Puppet Enterprise 2.0 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Oracle Enterprise Linux 5 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 IBM Websphere Portal 6.1 IBM Websphere Application Server 8.0 2 IBM Websphere Application Server 7.0 3 IBM Websphere Application Server 7.0 21 IBM Websphere Application Server 7.0 .2 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.0 IBM Websphere Application Server 8.0.0.4 IBM Websphere Application Server 8.0 IBM Websphere Application Server 7.0.0.23 IBM Websphere Application Server 7.0.0.19 IBM Websphere Application Server 7.0.0.17 IBM Websphere Application Server 7.0.0.14 IBM Websphere Application Server 7.0.0.13 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0.0.0 IBM Websphere Application Server 7.0 IBM Websphere Application Server 6.1 IBM OS/400 V6R1M0 HP HP-UX B.11.31 HP HP-UX B.11.23 Gentoo Linux Cosmicperl Directory Pro 10.0.3 CentOS CentOS 6 CentOS CentOS 5 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Experience Portal 6.0 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.5.8 Apple Mac OS X 10.5.7 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 3 Apple Mac OS X 10.0 Apple Mac Os X 10.7.4 Apple Mac Os X 10.7.3 Apple Mac Os X 10.7.2 Apple Mac Os X 10.7.1 Apple Mac OS X 10.6 Apple Mac OS X 10.5 Apache Software Foundation Apache 2.3.6 Apache Software Foundation Apache 2.3.5 Apache Software Foundation Apache 2.3.4 Apache Software Foundation Apache 2.3.2 Apache Software Foundation Apache 2.3.1 Apache Software Foundation Apache 2.3 Apache Software Foundation Apache 2.2.15 Apache Software Foundation Apache 2.2.14 Apache Software Foundation Apache 2.2.13 Apache Software Foundation Apache 2.2.12 Apache Software Foundation Apache 2.2.11 Apache Software Foundation Apache 2.2.10 Apache Software Foundation Apache 2.2.9 Apache Software Foundation Apache 2.2.8 Apache Software Foundation Apache 2.2.6 Apache Software Foundation Apache 2.2.4 Apache Software Foundation Apache 2.2.3 Apache Software Foundation Apache 2.2.2 Apache Software Foundation Apache 2.2 Apache Software Foundation Apache 2.1.9 Apache Software Foundation Apache 2.1.8 Apache Software Foundation Apache 2.1.7 Apache Software Foundation Apache 2.1.6 Apache Software Foundation Apache 2.1.5 Apache Software Foundation Apache 2.1.4 Apache Software Foundation Apache 2.1.3 Apache Software Foundation Apache 2.1.2 Apache Software Foundation Apache 2.1.1 Apache Software Foundation Apache 2.1 Apache Software Foundation Apache 2.0.63 Apache Software Foundation Apache 2.0.61 Apache Software Foundation Apache 2.0.60 Apache Software Foundation Apache 2.0.59 Apache Software Foundation Apache 2.0.58 Apache Software Foundation Apache 2.0.57 Apache Software Foundation Apache 2.0.56 Apache Software Foundation Apache 2.0.55 Apache Software Foundation Apache 2.0.54 Apache Software Foundation Apache 2.0.53 Apache Software Foundation Apache 2.0.52 Apache Software Foundation Apache 2.0.51 Apache Software Foundation Apache 2.0.50 Apache Software Foundation Apache 2.0.49 Apache Software Foundation Apache 2.0.48 Apache Software Foundation Apache 2.0.47 Apache Software Foundation Apache 2.0.46 Apache Software Foundation Apache 2.0.45 Apache Software Foundation Apache 2.0.44 Apache Software Foundation Apache 2.0.43 Apache Software Foundation Apache 2.0.42 Apache Software Foundation Apache 2.0.41 Apache Software Foundation Apache 2.0.40 Apache Software Foundation Apache 2.0.39 Apache Software Foundation Apache 2.0.38 Apache Software Foundation Apache 2.0.37 Apache Software Foundation Apache 2.0.36 Apache Software Foundation Apache 2.0.35 Apache Software Foundation Apache 2.0.34 -BETA Apache Software Foundation Apache 2.0.32 -BETA Apache Software Foundation Apache 2.0.32 Apache Software Foundation Apache 2.0.28 -BETA Apache Software Foundation Apache 2.0.28 Beta Apache Software Foundation Apache 2.0.28 Apache Software Foundation Apache 2.0.9 Apache Software Foundation Apache 2.0 Apache Software Foundation Apache 2.4.2 Apache Software Foundation Apache 2.3.3 Apache Software Foundation Apache 2.2.22 Apache Software Foundation Apache 2.2.21 Apache Software Foundation Apache 2.2.21 Apache Software Foundation Apache 2.2.20 Apache Software Foundation Apache 2.2.19 Apache Software Foundation Apache 2.2.18 Apache Software Foundation Apache 2.2.17 Apache Software Foundation Apache 2.2.16 Apache Software Foundation Apache 2.2.1 Apache Software Foundation Apache 2.2 Apache Software Foundation Apache 2.0.64 |
| Not Vulnerable: | |
Discussion
Apache HTTP Server Multiple Denial of Service Vulnerabilities
Apache HTTP Server is prone to multiple denial-of-service vulnerabilities.
Successful exploits may allow an attacker to cause an affected application to crash, resulting in a denial-of-service condition.
Apache HTTP Server 2.4.7, 2.4.6, 2.4.4, 2.4.3, 2.4.2, and 2.4.1 are vulnerable.
Apache HTTP Server is prone to multiple denial-of-service vulnerabilities.
Successful exploits may allow an attacker to cause an affected application to crash, resulting in a denial-of-service condition.
Apache HTTP Server 2.4.7, 2.4.6, 2.4.4, 2.4.3, 2.4.2, and 2.4.1 are vulnerable.
Exploit / POC
Apache HTTP Server Multiple Denial of Service Vulnerabilities
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Apache HTTP Server Multiple Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache HTTP Server Multiple Denial of Service Vulnerabilities
References:
References: