Apache Web Server OS2 Filestat Denial Of Service Vulnerability
BID:7332
Info
Apache Web Server OS2 Filestat Denial Of Service Vulnerability
| Bugtraq ID: | 7332 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0134 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2003 12:00AM |
| Updated: | Jul 11 2009 09:06PM |
| Credit: | Discovery of this issue is credited to Robert Howard <[email protected]>. |
| Vulnerable: |
Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 |
| Not Vulnerable: |
Apache Apache 2.0.46 |
Discussion
Apache Web Server OS2 Filestat Denial Of Service Vulnerability
The Apache Software Foundation has reported a denial of service vulnerability on Apache for OS2 platforms. It is reported that device names can fault the OS2 worker process, which could result in a denial of service condition.
The Apache Software Foundation has reported a denial of service vulnerability on Apache for OS2 platforms. It is reported that device names can fault the OS2 worker process, which could result in a denial of service condition.
Exploit / POC
Apache Web Server OS2 Filestat Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache Web Server OS2 Filestat Denial Of Service Vulnerability
Solution:
Apache has released a patch to address this issue.
Fixes available:
Apache Apache 2.0.35
Apache Apache 2.0.36
Apache Apache 2.0.37
Apache Apache 2.0.38
Apache Apache 2.0.39
Apache Apache 2.0.40
Apache Apache 2.0.41
Apache Apache 2.0.42
Apache Apache 2.0.43
Apache Apache 2.0.44
Apache Apache 2.0.45
Solution:
Apache has released a patch to address this issue.
Fixes available:
Apache Apache 2.0.35
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.36
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.37
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.38
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.39
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.40
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.41
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.42
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.43
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.44
-
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
Apache Apache 2.0.45
-
Apache Software Foundation os2_filestat_security_fix.patch
http://www.apache.org/dist/httpd/patches/apply_to_2.0.45/os2_filestat_ security_fix.patch -
Apache Software Foundation Apache httpd 2.0.46
http://www.apache.org/dist/httpd/
References
Apache Web Server OS2 Filestat Denial Of Service Vulnerability
References:
References:
- Apache 2.0.45 Released (Apache Software Foundation)
- Apache Homepage (Apache Software Foundation)
- PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service Vulnerability ("William A. Rowe, Jr."
)