Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
BID:8138
Info
Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
| Bugtraq ID: | 8138 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 08 2003 12:00AM |
| Updated: | Jul 08 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Keigo Yamazaki. |
| Vulnerable: |
Apache Apache 2.0.46 Apache Apache 2.0.45 Apache Apache 2.0.44 Apache Apache 2.0.43 Apache Apache 1.3.27 Apache Apache 1.3.26 Apache Apache 1.3.25 Apache Apache 1.3.24 Apache Apache 1.3.23 Apache Apache 1.3.22 Apache Apache 1.3.20 |
| Not Vulnerable: |
Apache Apache 2.0.47 Apache Apache 1.3.28 |
Discussion
Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
Apache content negotiation functionality reported prone to a denial of service vulnerability.
Under certain circumstances a local attacker may cause the vulnerable Apache server to fall into an infinite loop and consume resources exponentially. Effectively denying service to other legitimate system users.
Apache content negotiation functionality reported prone to a denial of service vulnerability.
Under certain circumstances a local attacker may cause the vulnerable Apache server to fall into an infinite loop and consume resources exponentially. Effectively denying service to other legitimate system users.
Exploit / POC
Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
Solution:
The vendor has addressed this issue with the release of Apache 2.0.47.
Conectiva has released advisory CLA-2003:704 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
Mandrake has released advisory MDKSA-2003:075 to address this issue. See referenced advisory for additional details and fix information.
Conectiva has released advisory CLA-2003:698 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
HP has released advisory HPSBUX0310-285 to address this issue.
Apache Apache 1.3.27
Apache Apache 2.0.43
Apache Apache 2.0.44
Apache Apache 2.0.45
Apache Apache 2.0.46
Solution:
The vendor has addressed this issue with the release of Apache 2.0.47.
Conectiva has released advisory CLA-2003:704 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
Mandrake has released advisory MDKSA-2003:075 to address this issue. See referenced advisory for additional details and fix information.
Conectiva has released advisory CLA-2003:698 to address this issue. Further information regarding obtaining and applying fixes can be found in the referenced advisory.
HP has released advisory HPSBUX0310-285 to address this issue.
Apache Apache 1.3.27
-
HP PHSS_29541
11.04 Virtualvault 4.5 IWS Update
http://itrc.hp.com -
HP PHSS_29542
11.04 Virtualvault 4.6 IWS update
http://itrc.hp.com -
HP PHSS_29545
11.04 Virtualvault 4.5 OWS update
http://itrc.hp.com -
HP PHSS_29546
11.04 Virtualvault 4.6 OWS update
http://itrc.hp.com -
HP PHSS_29547
11.04 Webproxy server 2.0 update
http://itrc.hp.com
Apache Apache 2.0.43
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.44
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
Apache Apache 2.0.45
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi -
Conectiva apache-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-2.0.45-28790U90_3cl. i386.rpm -
Conectiva apache-2.0.45-28790U90_3cl.src.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/SRPMS/apache-2.0.45-28790U90_3cl .src.rpm -
Conectiva apache-devel-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-devel-2.0.45-28790U9 0_3cl.i386.rpm -
Conectiva apache-doc-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-doc-2.0.45-28790U90_ 3cl.i386.rpm -
Conectiva apache-htpasswd-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-htpasswd-2.0.45-2879 0U90_3cl.i386.rpm -
Conectiva libapr-devel-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-2.0.45-28790U9 0_3cl.i386.rpm -
Conectiva libapr-devel-static-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-static-2.0.45- 28790U90_3cl.i386.rpm -
Conectiva libapr0-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr0-2.0.45-28790U90_3cl .i386.rpm -
Conectiva mod_auth_ldap-2.0.45-28790U90_3cl.i386.rpm
Conectiva Linux 9
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_auth_ldap-2.0.45-28790U 90_3cl.i386.rpm
Apache Apache 2.0.46
-
Apache Software Foundation Apache httpd 2.0.47
http://httpd.apache.org/download.cgi
References
Apache Web Server Type-Map Recursive Loop Denial Of Service Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Apache httpd Release 2.0 Changes (Apache Software Foundation)
- SNS Advisory No.66 (SNS)