Apache Error Log Escape Sequence Injection Vulnerability
BID:9930
Info
Apache Error Log Escape Sequence Injection Vulnerability
| Bugtraq ID: | 9930 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0020 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2004 12:00AM |
| Updated: | Feb 17 2010 08:32PM |
| Credit: | The individual responsible for the disclosure of this issue is currently not known. |
| Vulnerable: |
Turbolinux Turbolinux Desktop 10.0 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc OpenBSD OpenBSD 3.5 OpenBSD OpenBSD 3.4 OpenBSD OpenBSD -current HP Webproxy A.02.10 HP Webproxy A.02.00 HP VirtualVault A.04.70 HP VirtualVault A.04.60 HP VirtualVault A.04.50 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X 10.3.3 Apple Mac OS X 10.2.8 Apache Software Foundation Apache 2.0.48 Apache Software Foundation Apache 2.0.47 Apache Software Foundation Apache 2.0.46 Apache Software Foundation Apache 2.0.45 Apache Software Foundation Apache 2.0.44 Apache Software Foundation Apache 2.0.43 Apache Software Foundation Apache 2.0.42 Apache Software Foundation Apache 2.0.41 Apache Software Foundation Apache 2.0.40 Apache Software Foundation Apache 2.0.39 Apache Software Foundation Apache 2.0.38 Apache Software Foundation Apache 2.0.37 Apache Software Foundation Apache 2.0.36 Apache Software Foundation Apache 2.0.35 Apache Software Foundation Apache 2.0.32 Apache Software Foundation Apache 2.0.28 Beta Apache Software Foundation Apache 2.0.28 Apache Software Foundation Apache 2.0 a9 Apache Software Foundation Apache 2.0 Apache Software Foundation Apache 1.3.29 Apache Software Foundation Apache 1.3.28 Apache Software Foundation Apache 1.3.27 Apache Software Foundation Apache 1.3.26 Apache Software Foundation Apache 1.3.25 Apache Software Foundation Apache 1.3.24 Apache Software Foundation Apache 1.3.23 Apache Software Foundation Apache 1.3.22 Apache Software Foundation Apache 1.3.20 Apache Software Foundation Apache 1.3.19 Apache Software Foundation Apache 1.3.18 Apache Software Foundation Apache 1.3.17 Apache Software Foundation Apache 1.3.14 Apache Software Foundation Apache 1.3.12 Apache Software Foundation Apache 1.3.11 Apache Software Foundation Apache 1.3.9 Apache Software Foundation Apache 1.3.7 -dev Apache Software Foundation Apache 1.3.6 Apache Software Foundation Apache 1.3.4 Apache Software Foundation Apache 1.3.3 Apache Software Foundation Apache 1.3.1 Apache Software Foundation Apache 1.3 |
| Not Vulnerable: |
Posadis Posadis 1.3.31 Apache Software Foundation Apache 2.0.49 Apache Software Foundation Apache 1.3.31 |
Discussion
Apache Error Log Escape Sequence Injection Vulnerability
Apache webserver is prone to a vulnerability that may allow remote attackers to inject escape sequences into Apache log files. This may facilitate exploitation of issues such as those found in BIDs 6936 and 6938.
Successful exploits may allow attackers to create arbitrary files and execute code on the affected system.
Apache webserver is prone to a vulnerability that may allow remote attackers to inject escape sequences into Apache log files. This may facilitate exploitation of issues such as those found in BIDs 6936 and 6938.
Successful exploits may allow attackers to create arbitrary files and execute code on the affected system.
Exploit / POC
Apache Error and Access Logs Escape Sequence Injection Vulnerability
No exploit is required to inject escape sequences into Apache logs.
No exploit is required to inject escape sequences into Apache logs.
Solution / Fix
Apache Error and Access Logs Escape Sequence Injection Vulnerability
Solution:
The vendor has released an upgrade. Please see the references for details.
OpenBSD OpenBSD 3.5
OpenBSD OpenBSD 3.4
Sun Solaris 9_x86
Apache Software Foundation Apache 1.3
Apache Software Foundation Apache 1.3.1
Apache Software Foundation Apache 1.3.14
Apache Software Foundation Apache 1.3.17
Apache Software Foundation Apache 1.3.22
Apache Software Foundation Apache 1.3.23
Apache Software Foundation Apache 1.3.25
Apache Software Foundation Apache 1.3.26
Apache Software Foundation Apache 1.3.27
Apache Software Foundation Apache 1.3.28
Apache Software Foundation Apache 1.3.29
Apache Software Foundation Apache 1.3.3
Apache Software Foundation Apache 1.3.4
Apache Software Foundation Apache 1.3.7 -dev
Turbolinux Turbolinux Desktop 10.0
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X 10.3.3
Apple Mac OS X Server 10.3.3
Apache Software Foundation Apache 2.0
Apache Software Foundation Apache 2.0 a9
Apache Software Foundation Apache 2.0.28
Apache Software Foundation Apache 2.0.28 Beta
Apache Software Foundation Apache 2.0.32
Apache Software Foundation Apache 2.0.35
Apache Software Foundation Apache 2.0.36
Apache Software Foundation Apache 2.0.37
Apache Software Foundation Apache 2.0.38
Apache Software Foundation Apache 2.0.39
Apache Software Foundation Apache 2.0.40
Apache Software Foundation Apache 2.0.41
Apache Software Foundation Apache 2.0.42
Apache Software Foundation Apache 2.0.43
Apache Software Foundation Apache 2.0.44
Apache Software Foundation Apache 2.0.45
Apache Software Foundation Apache 2.0.46
Apache Software Foundation Apache 2.0.47
Apache Software Foundation Apache 2.0.48
Solution:
The vendor has released an upgrade. Please see the references for details.
OpenBSD OpenBSD 3.5
-
OpenBSD 013_httpd.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.5/common/013_httpd.patch
OpenBSD OpenBSD 3.4
-
OpenBSD 025_httpd3.patch
ftp://ftp.openbsd.org/pub/OpenBSD/patches/3.4/common/025_httpd3.patch
Sun Solaris 9_x86
-
Sun T-patch T114145-04.tar.Z
http://sunsolve.sun.com/pub-cgi/show.pl?target=security/tpatches -
Sun 114145-04
http://sunsolve.sun.com/search/pdownload.pl?target=114145-04&method=hs
Apache Software Foundation Apache 1.3
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 1.3.1
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 1.3.14
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 1.3.17
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 1.3.22
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 1.3.23
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 1.3.25
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 1.3.26
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi -
Mandrake apache-mod_perl-1.3.26_1.27-7.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache-mod_perl-1.3.26_1.27-7.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.26_1.3.4-7.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.26_1.3.4-7.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.26_1.27-7.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.26_1.27-7.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.26_1.27-7.1.C21mdk.i586.rpm
Mandrake Corporate Server 2.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.26_1.27-7.1.C21mdk.x86_64.rpm
Mandrake Corporate Server 2.1/X86_64
http://www.mandrakesecure.net/en/ftp.php
Apache Software Foundation Apache 1.3.27
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi -
Mandrake apache-mod_perl-1.3.27_1.27-7.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache-mod_perl-1.3.27_1.27-7.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.27_1.3.4-7.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.27_1.3.4-7.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.27_1.27-7.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.27_1.27-7.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.27_1.27-7.1.91mdk.i586.rpm
Mandrake Linux 9.1
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.27_1.27-7.1.91mdk.ppc.rpm
Mandrake Linux 9.1/PPC
http://www.mandrakesecure.net/en/ftp.php -
TurboLinux apache-1.3.27-23.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/apache-1.3.27-23.i386.rpm -
TurboLinux apache-1.3.27-23.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/apache-1.3.27-23.i386.rpm -
TurboLinux apache-1.3.27-23.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/upd ates/RPMS/apache-1.3.27-23.i386.rpm -
TurboLinux apache-1.3.27-23.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/6. 0/ja/updates/RPMS/apache-1.3.27-23.i386.rpm -
TurboLinux apache-1.3.27-23.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/apache-1.3.27-23.i586.rpm -
TurboLinux apache-1.3.27-23.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/apache-1.3.27-23.i586.rpm -
TurboLinux apache-1.3.27-23.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/ updates/RPMS/apache-1.3.27-23.i586.rpm -
TurboLinux apache-1.3.27-23.i586.rpm
Turbolinux 8 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/apache-1.3.27-23.i586.rpm -
TurboLinux apache-devel-1.3.27-23.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/apache-devel-1.3.27-23.i386.rpm -
TurboLinux apache-devel-1.3.27-23.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/apache-devel-1.3.27-23.i386.rpm -
TurboLinux apache-devel-1.3.27-23.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/upd ates/RPMS/apache-devel-1.3.27-23.i386.rpm -
TurboLinux apache-devel-1.3.27-23.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/6. 0/ja/updates/RPMS/apache-devel-1.3.27-23.i386.rpm -
TurboLinux apache-devel-1.3.27-23.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/apache-devel-1.3.27-23.i586.rpm -
TurboLinux apache-devel-1.3.27-23.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/apache-devel-1.3.27-23.i586.rpm -
TurboLinux apache-devel-1.3.27-23.i586.rpm
Turbolinux 8 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/apache-devel-1.3.27-23.i586.rpm -
TurboLinux apache-manual-1.3.27-23.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/apache-manual-1.3.27-23.i386.rpm -
TurboLinux apache-manual-1.3.27-23.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/apache-manual-1.3.27-23.i386.rpm -
TurboLinux apache-manual-1.3.27-23.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/upd ates/RPMS/apache-manual-1.3.27-23.i386.rpm -
TurboLinux apache-manual-1.3.27-23.i386.rpm
Turbolinux Workstation 6.0
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/6. 0/ja/updates/RPMS/apache-manual-1.3.27-23.i386.rpm -
TurboLinux apache-manual-1.3.27-23.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/apache-manual-1.3.27-23.i586.rpm -
TurboLinux apache-manual-1.3.27-23.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/apache-manual-1.3.27-23.i586.rpm -
TurboLinux apache-manual-1.3.27-23.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/ updates/RPMS/apache-manual-1.3.27-23.i586.rpm -
TurboLinux apache-manual-1.3.27-23.i586.rpm
Turbolinux 8 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/apache-manual-1.3.27-23.i586.rpm -
TurboLinux mod_ssl-2.8.14-23.i386.rpm
Turbolinux Advanced Server 6
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/AdvancedServer /6/ja/updates/RPMS/mod_ssl-2.8.14-23.i386.rpm -
TurboLinux mod_ssl-2.8.14-23.i386.rpm
Turbolinux Server 6.1
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.1/ja/ updates/RPMS/mod_ssl-2.8.14-23.i386.rpm -
TurboLinux mod_ssl-2.8.14-23.i386.rpm
Turbolinux Server 6.5
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/6.5/upd ates/RPMS/mod_ssl-2.8.14-23.i386.rpm -
TurboLinux mod_ssl-2.8.14-23.i586.rpm
Turbolinux 7 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/7/updat es/RPMS/mod_ssl-2.8.14-23.i586.rpm -
TurboLinux mod_ssl-2.8.14-23.i586.rpm
Turbolinux 8 Server
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Server/8/updat es/RPMS/mod_ssl-2.8.14-23.i586.rpm -
TurboLinux mod_ssl-2.8.14-23.i586.rpm
Turbolinux 7 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/7/ updates/RPMS/mod_ssl-2.8.14-23.i586.rpm -
TurboLinux mod_ssl-2.8.14-23.i586.rpm
Turbolinux 8 Workstation
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Workstation/8/ updates/RPMS/mod_ssl-2.8.14-23.i586.rpm
Apache Software Foundation Apache 1.3.28
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi -
Conectiva apache-1.3.28-1U80_3cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/apache-1.3.28-1U80_3cl.i386 .rpm -
Conectiva apache-devel-1.3.28-1U80_3cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/apache-devel-1.3.28-1U80_3c l.i386.rpm -
Conectiva apache-doc-1.3.28-1U80_3cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/8/RPMS/apache-doc-1.3.28-1U80_3cl. i386.rpm -
Mandrake apache-mod_perl-1.3.28_1.28-1.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache-mod_perl-1.3.28_1.28-1.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.28_1.3.4-1.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.28_1.3.4-1.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.28_1.28-1.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.28_1.28-1.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.28_1.28-1.1.92mdk.amd64.rpm
Mandrake Linux 9.2/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.28_1.28-1.1.92mdk.i586.rpm
Mandrake Linux 9.2
http://www.mandrakesecure.net/en/ftp.php
Apache Software Foundation Apache 1.3.29
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi -
Apple SecUpd2004-12-02Jag.dmg
For Mac OS X v10.2.8:
http://www.apple.com/support/downloads/SecUpd2004-12-02Jag.dmg -
Apple SecUpd2004-12-02Pan.dmg
For Mac OS X v10.3.6:
http://www.apple.com/support/downloads/SecUpd2004-12-02Pan.dmg -
Apple SecUpdSrvr2004-12-02Jag.dmg
For Mac OS X Server v10.2.8:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Jag.dmg -
Apple SecUpdSrvr2004-12-02Pan.dmg
For Mac OS X Server v10.3.6:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Pan.dmg -
Mandrake apache-mod_perl-1.3.29_1.29-3.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake apache-mod_perl-1.3.29_1.29-3.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.29_1.3.6-3.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake HTML-Embperl-1.3.29_1.3.6-3.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.29_1.29-3.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-common-1.3.29_1.29-3.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.29_1.29-3.1.100mdk.amd64.rpm
Mandrake Linux 10.0/AMD64
http://www.mandrakesecure.net/en/ftp.php -
Mandrake mod_perl-devel-1.3.29_1.29-3.1.100mdk.i586.rpm
Mandrake Linux 10.0
http://www.mandrakesecure.net/en/ftp.php -
Slackware apache-1.3.29-i386-2.tgz
Updated package for Slackware 8.1:
ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/a pache-1.3.29-i386-2.tgz -
Slackware apache-1.3.29-i386-2.tgz for Slackware 9.0
Updated package for Slackware 9.0
ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/a pache-1.3.29-i386-2.tgz -
Slackware apache-1.3.29-i486-2.tgz
Updated package for Slackware 9.1
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/a pache-1.3.29-i486-2.tgz
Apache Software Foundation Apache 1.3.3
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 1.3.4
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 1.3.7 -dev
-
Apache Software Foundation apache 1.3.31
http://httpd.apache.org/download.cgi
Turbolinux Turbolinux Desktop 10.0
-
Turbolinux httpd-2.0.47-8.i586.rpm
ftp://ftp.turbolinux.com/pub/TurboLinux/TurboLinux/ia32/Desktop/10/upd ates/RPMS/httpd-2.0.47-8.i586.rpm
Apple Mac OS X 10.2.8
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg -
Apple SecUpd2004-12-02Jag.dmg
For Mac OS X v10.2.8:
http://www.apple.com/support/downloads/SecUpd2004-12-02Jag.dmg -
Apple SecUpd2004-12-02Pan.dmg
For Mac OS X v10.3.6:
http://www.apple.com/support/downloads/SecUpd2004-12-02Pan.dmg -
Apple SecUpdSrvr2004-12-02Jag.dmg
For Mac OS X Server v10.2.8:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Jag.dmg -
Apple SecUpdSrvr2004-12-02Pan.dmg
For Mac OS X Server v10.3.6:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Pan.dmg
Apple Mac OS X Server 10.2.8
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg -
Apple SecUpd2004-12-02Jag.dmg
For Mac OS X v10.2.8:
http://www.apple.com/support/downloads/SecUpd2004-12-02Jag.dmg -
Apple SecUpd2004-12-02Pan.dmg
For Mac OS X v10.3.6:
http://www.apple.com/support/downloads/SecUpd2004-12-02Pan.dmg -
Apple SecUpdSrvr2004-12-02Jag.dmg
For Mac OS X Server v10.2.8:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Jag.dmg -
Apple SecUpdSrvr2004-12-02Pan.dmg
For Mac OS X Server v10.3.6:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Pan.dmg
Apple Mac OS X 10.3.3
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg -
Apple SecUpd2004-12-02Jag.dmg
For Mac OS X v10.2.8:
http://www.apple.com/support/downloads/SecUpd2004-12-02Jag.dmg
Apple Mac OS X Server 10.3.3
-
Apple SecUpd2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1217.20040503.BmkY5/2Z/Sec Upd2004-05-03Jag.dmg -
Apple SecUpd2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1213.20040503.vngr3/2Z/Sec Upd2004-05-03Pan.dmg -
Apple SecUpdSrvr2004-05-03Jag.dmg
http://download.info.apple.com/Mac_OS_X/061-1219.20040503.Zsw3S/2Z/Sec UpdSrvr2004-05-03Jag.dmg -
Apple SecUpdSrvr2004-05-03Pan.dmg
http://download.info.apple.com/Mac_OS_X/061-1215.20040503.mPp9k/2Z/Sec UpdSrvr2004-05-03Pan.dmg
Apache Software Foundation Apache 2.0
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0 a9
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.28
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.28 Beta
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.32
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.35
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.36
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.37
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.38
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.39
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.40
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.41
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.42
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.43
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.44
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.45
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi -
Conectiva apache-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-2.0.45-28790U90_6cl. i386.rpm -
Conectiva apache-devel-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-devel-2.0.45-28790U9 0_6cl.i386.rpm -
Conectiva apache-doc-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-doc-2.0.45-28790U90_ 6cl.i386.rpm -
Conectiva apache-htpasswd-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/apache-htpasswd-2.0.45-2879 0U90_6cl.i386.rpm -
Conectiva libapr-devel-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-2.0.45-28790U9 0_6cl.i386.rpm -
Conectiva libapr-devel-static-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr-devel-static-2.0.45- 28790U90_6cl.i386.rpm -
Conectiva libapr0-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/libapr0-2.0.45-28790U90_6cl .i386.rpm -
Conectiva mod_auth_ldap-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_auth_ldap-2.0.45-28790U 90_6cl.i386.rpm -
Conectiva mod_dav-2.0.45-28790U90_6cl.i386.rpm
ftp://atualizacoes.conectiva.com.br/9/RPMS/mod_dav-2.0.45-28790U90_6cl .i386.rpm
Apache Software Foundation Apache 2.0.46
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi
Apache Software Foundation Apache 2.0.47
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi -
Apple SecUpd2004-12-02Jag.dmg
For Mac OS X v10.2.8:
http://www.apple.com/support/downloads/SecUpd2004-12-02Jag.dmg -
Apple SecUpd2004-12-02Pan.dmg
For Mac OS X v10.3.6:
http://www.apple.com/support/downloads/SecUpd2004-12-02Pan.dmg -
Apple SecUpdSrvr2004-12-02Jag.dmg
For Mac OS X Server v10.2.8:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Jag.dmg -
Apple SecUpdSrvr2004-12-02Pan.dmg
For Mac OS X Server v10.3.6:
http://www.apple.com/support/downloads/SecUpdSrvr2004-12-02Pan.dmg
Apache Software Foundation Apache 2.0.48
-
Apache Software Foundation Apache httpd 2.0.49
http://httpd.apache.org/download.cgi -
Trustix apache-2.0.49-1tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.0/rpms/apache-2.0.49-1tr.i 586.rpm -
Trustix apache-2.0.49-2tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.1/rpms/apache-2.0.49-2tr.i 586.rpm -
Trustix apache-dbm-2.0.49-2tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.1/rpms/apache-dbm-2.0.49-2 tr.i586.rpm -
Trustix apache-devel-2.0.49-1tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.0/rpms/apache-devel-2.0.49 -1tr.i586.rpm -
Trustix apache-devel-2.0.49-2tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.1/rpms/apache-devel-2.0.49 -2tr.i586.rpm -
Trustix apache-manual-2.0.49-1tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.0/rpms/apache-manual-2.0.4 9-1tr.i586.rpm -
Trustix apache-manual-2.0.49-2tr.i586.rpm
ftp://ftp.trustix.org/pub/trustix/updates/2.1/rpms/apache-manual-2.0.4 9-2tr.i586.rpm
References
Apache Error and Access Logs Escape Sequence Injection Vulnerability
References:
References:
- Apache Homepage (Apache Software Foundation)
- Apache HTTP Server 2.0.49 Released (Apache Software Foundation)
- CLSA-2004:839 - apache (Conectiva)
- OpenBSD Errata Page (OpenBSD)
- Sun Alert ID: 57628 (Sun)
- Terminal Emulator Security Issues (H D Moore
)