Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Производитель ПО
Наименование ПО
Apache HTTP Server
(2.0.0, 2.0.45)
Описание
Утечка памяти в Apache позволяет злоумышленникам, действующим удаленно, вызвать отказ в обслуживании (чрезмерное потребление ресурсов памяти), используя длинные последовательности символов перевода строки, т.к. Apache выделяет 80 байт для каждого символа перевода строки.
Как исправить
Для устранения уязвимости необходимо установить последнюю версию продукта, соответствующую используемой платформе. Необходимую информацию можно получить по адресу:
http://www.apache.org/
http://www.apache.org/
Ссылки
The Aims Group (Apache 2.0.45 Released): http://marc.theaimsgroup.com/?l=bugtraq&m=104931360606484&w=2
Security Focus (bid 7254): http://www.securityfocus.com/bid/7254
MISC (http://www.idefense.com/advisory/04.08.03.txt): http://www.idefense.com/advisory/04.08.03.txt
REDHAT (RHSA-2003:139): http://www.redhat.com/support/errata/RHSA-2003-139.html
CONFIRM (http://lists.apple.com/mhonarc/security-announce/msg00028.html): http://lists.apple.com/mhonarc/security-announce/msg00028.html
OVAL (OVAL156): http://oval.mitre.org/oval/definitions/data/oval156.html
CERT-VN (VU#206537): http://www.kb.cert.org/vuls/id/206537
BUGTRAQ (20030408 iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x): http://marc.theaimsgroup.com/?l=bugtraq&m=104982175321731&w=2
BUGTRAQ (20030408 Exploit Code Released for Apache 2.x Memory Leak): http://marc.theaimsgroup.com/?l=bugtraq&m=104994309010974&w=2
BUGTRAQ (20030409 GLSA: apache (200304-01)): http://marc.theaimsgroup.com/?l=bugtraq&m=104994239010517&w=2
BUGTRAQ (20030410 working apache <= 2.0.44 DoS exploit for linux.): http://marc.theaimsgroup.com/?l=bugtraq&m=105001663120995&w=2
BUGTRAQ (20030411 PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service): http://marc.theaimsgroup.com/?l=bugtraq&m=105013378320711&w=2
OVAL (oval:org.mitre.oval:def:156): http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:156
Security Focus (bid 7254): http://www.securityfocus.com/bid/7254
MISC (http://www.idefense.com/advisory/04.08.03.txt): http://www.idefense.com/advisory/04.08.03.txt
REDHAT (RHSA-2003:139): http://www.redhat.com/support/errata/RHSA-2003-139.html
CONFIRM (http://lists.apple.com/mhonarc/security-announce/msg00028.html): http://lists.apple.com/mhonarc/security-announce/msg00028.html
OVAL (OVAL156): http://oval.mitre.org/oval/definitions/data/oval156.html
CERT-VN (VU#206537): http://www.kb.cert.org/vuls/id/206537
BUGTRAQ (20030408 iDEFENSE Security Advisory 04.08.03: Denial of Service in Apache HTTP Server 2.x): http://marc.theaimsgroup.com/?l=bugtraq&m=104982175321731&w=2
BUGTRAQ (20030408 Exploit Code Released for Apache 2.x Memory Leak): http://marc.theaimsgroup.com/?l=bugtraq&m=104994309010974&w=2
BUGTRAQ (20030409 GLSA: apache (200304-01)): http://marc.theaimsgroup.com/?l=bugtraq&m=104994239010517&w=2
BUGTRAQ (20030410 working apache <= 2.0.44 DoS exploit for linux.): http://marc.theaimsgroup.com/?l=bugtraq&m=105001663120995&w=2
BUGTRAQ (20030411 PATCH: [CAN-2003-0132] Apache 2.0.44 Denial of Service): http://marc.theaimsgroup.com/?l=bugtraq&m=105013378320711&w=2
OVAL (oval:org.mitre.oval:def:156): http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:156