Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Производитель ПО
Наименование ПО
Apache HTTP Server
(Unix - 2.0.37, Unix - 2.0.46)
Описание
Уязвимость в функции apr_psprintf в библиотеке Apache Portable Runtime (APR) в Apache позволяет злоумышленникам, действующим удаленно, вызвать отказ в обслуживании (аварийное завершение) и, возможно, выполнить произвольный код, используя длинные строки, например, XML-объекты в mod_dav, и, возможно, через другие вектора.
Как исправить
Для устранения уязвимости необходимо установить последнюю версию продукта, соответствующую используемой платформе. Необходимую информацию можно получить по адресу:
http://www.apache.org/
http://www.apache.org/
Ссылки
Apache http://www.apache.org/dist/httpd/Announcement2.html
Bugtraq (20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released): http://marc.theaimsgroup.com/?l=bugtraq&m=105418115512559&w=2
Red Hat (RHSA-2003:186): http://www.redhat.com/support/errata/RHSA-2003-186.html
CERT (Apache Portable Runtime contains heap buffer overflow in apr_psprintf()): http://www.kb.cert.org/vuls/id/757612
ISS X-Force (Apache HTTP Server apr_psprintf code execution): http://xforce.iss.net/xforce/xfdb/12090
VULNWATCH (20030530 iDEFENSE Security Advisory 05.30.03: Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability): http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0095.html
MISC (http://www.idefense.com/advisory/05.30.03.txt): http://www.idefense.com/advisory/05.30.03.txt
MANDRAKE (MDKSA-2003:063): http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:063
BID (7723): http://www.securityfocus.com/bid/7723
CONECTIVA (CLA-2003:661): http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000661
Bugtraq (20030528 [SECURITY] [ANNOUNCE] Apache 2.0.46 released): http://marc.theaimsgroup.com/?l=bugtraq&m=105418115512559&w=2
Red Hat (RHSA-2003:186): http://www.redhat.com/support/errata/RHSA-2003-186.html
CERT (Apache Portable Runtime contains heap buffer overflow in apr_psprintf()): http://www.kb.cert.org/vuls/id/757612
ISS X-Force (Apache HTTP Server apr_psprintf code execution): http://xforce.iss.net/xforce/xfdb/12090
VULNWATCH (20030530 iDEFENSE Security Advisory 05.30.03: Apache Portable Runtime Denial of Service and Arbitrary Code Execution Vulnerability): http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0095.html
MISC (http://www.idefense.com/advisory/05.30.03.txt): http://www.idefense.com/advisory/05.30.03.txt
MANDRAKE (MDKSA-2003:063): http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:063
BID (7723): http://www.securityfocus.com/bid/7723
CONECTIVA (CLA-2003:661): http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000661