Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
BID:8135
Info
Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
| Bugtraq ID: | 8135 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0254 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery of this vulnerability has been credited to Yoshioka Tsuneo <[email protected]>. |
| Vulnerable: |
Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 2.0.42 Apache Apache 2.0.41 Apache Apache 2.0.40 Apache Apache 2.0.39 Apache Apache 2.0.38 Apache Apache 2.0.37 Apache Apache 2.0.36 Apache Apache 2.0.35 Apache Apache 2.0.34 -BETA Apache Apache 2.0.32 -BETA Apache Apache 2.0.32 Apache Apache 2.0.28 -BETA Apache Apache 2.0.28 Beta Apache Apache 2.0.28 Apache Apache 2.0 a9 Apache Apache 2.0 |
| Not Vulnerable: |
Apache Apache 2.0.47 |
Discussion
Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
A denial of service vulnerability has been reported by the vendor to affect the FTP proxy component of Apache. It has been reported that an attacker may specify a target server that has got an IPV6 address format. This may result in a denial of service to other legitimate users.
A denial of service vulnerability has been reported by the vendor to affect the FTP proxy component of Apache. It has been reported that an attacker may specify a target server that has got an IPV6 address format. This may result in a denial of service to other legitimate users.
Exploit / POC
Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
Solution:
The vendor has addressed this issue with the release of Apache 2.0.47.
Conectiva has released advisory CLA-2003:698 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
Mandrake has released advisory MDKSA-2003:075 to address this issue. See referenced advisory for additional details and fix information.
Red Hat has released advisory RHSA-2003:240-01 to address this issue.
HP has released advisory HPSBUX0309-278 to address this issue.
Trustix has released advisory 2003-0025 to address this issue.
Apache Apache 2.0
Apache Apache 2.0 a9
Apache Apache 2.0.28 -BETA
Apache Apache 2.0.28
Apache Apache 2.0.28 Beta
Apache Apache 2.0.32
Apache Apache 2.0.32 -BETA
Apache Apache 2.0.34 -BETA
Apache Apache 2.0.35
Apache Apache 2.0.36
Apache Apache 2.0.37
Apache Apache 2.0.38
Apache Apache 2.0.39
Apache Apache 2.0.40
Apache Apache 2.0.41
Apache Apache 2.0.42
Apache Apache 2.0.43
Apache Apache 2.0.44
Apache Apache 2.0.45
Apache Apache 2.0.46
Solution:
The vendor has addressed this issue with the release of Apache 2.0.47.
Conectiva has released advisory CLA-2003:698 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
Mandrake has released advisory MDKSA-2003:075 to address this issue. See referenced advisory for additional details and fix information.
Red Hat has released advisory RHSA-2003:240-01 to address this issue.
HP has released advisory HPSBUX0309-278 to address this issue.
Trustix has released advisory 2003-0025 to address this issue.
Apache Apache 2.0
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0 a9
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.28 -BETA
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.28
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.28 Beta
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.32
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.32 -BETA
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.34 -BETA
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.35
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.36
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.37
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.38
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.39
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.40
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi -
Red Hat httpd-2.0.40-11.7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-2.0.40-11.7.i386.rpm -
Red Hat httpd-2.0.40-21.5.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-2.0.40-21.5.i386.rpm -
Red Hat httpd-devel-2.0.40-11.7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-devel-2.0.40-11.7.i386.r pm -
Red Hat httpd-devel-2.0.40-21.5.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-devel-2.0.40-21.5.i386.rpm -
Red Hat httpd-manual-2.0.40-11.7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/httpd-manual-2.0.40-11.7.i386. rpm -
Red Hat httpd-manual-2.0.40-21.5.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/httpd-manual-2.0.40-21.5.i386.rp m -
Red Hat mod_ssl-2.0.40-11.7.i386.rpm
ftp://updates.redhat.com/8.0/en/os/i386/mod_ssl-2.0.40-11.7.i386.rpm -
Red Hat mod_ssl-2.0.40-21.5.i386.rpm
ftp://updates.redhat.com/9/en/os/i386/mod_ssl-2.0.40-21.5.i386.rpm
Apache Apache 2.0.41
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.42
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.43
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.44
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.45
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi -
Conectiva apache-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-2.0.45-28790U90_3cl. i386.rpm -
Conectiva apache-2.0.45-28790U90_3cl.src.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/SRPMS/apache-2.0.45-28790U90_3cl .src.rpm -
Conectiva apache-devel-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-devel-2.0.45-28790U9 0_3cl.i386.rpm -
Conectiva apache-doc-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-doc-2.0.45-28790U90_ 3cl.i386.rpm -
Conectiva apache-htpasswd-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-htpasswd-2.0.45-2879 0U90_3cl.i386.rpm -
Conectiva libapr-devel-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-2.0.45-28790U9 0_3cl.i386.rpm -
Conectiva libapr-devel-static-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-static-2.0.45- 28790U90_3cl.i386.rpm -
Conectiva libapr0-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr0-2.0.45-28790U90_3cl .i386.rpm -
Conectiva mod_auth_ldap-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_auth_ldap-2.0.45-28790U 90_3cl.i386.rpm
Apache Apache 2.0.46
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi -
Trustix apache-2.0.47-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/2.0/RPMS/apache-2.0.47-2tr.i 586.rpm -
Trustix apache-devel-2.0.47-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/2.0/RPMS/apache-devel-2.0.47 -2tr.i586.rpm -
Trustix apache-manual-2.0.47-2tr.i586.rpm
ftp://ftp.trustix.net/pub/Trustix/updates/2.0/RPMS/apache-manual-2.0.4 7-2tr.i586.rpm
References
Apache Web Server FTP Proxy IPV6 Denial Of Service Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Apache httpd Release 2.0 Changes (Apache Software Foundation)