Apache HTTP Server Chunk Encoding Vulnerability
"Raynard A. Jong" <[email protected]> Wed, 19 Jun 2002 17:52:18 -0700
| Newsgroups | gmane.linux.redhat.stronghold |
|---|---|
| Message-ID | <p05100303b936d5c67187@[128.115.101.2]> |
Are versions of Stronghold also affected by the Apache vulnerability
recently announced by CIAC?
PROBLEM: The Apache HTTP Server has a software flaw that misinterprets
invalid requests encoded using chunked encoding. This error can
be triggered remotely by sending certain invalid requests.
PLATFORM: Any systems running Apache web server 1.3.24 and 2.0 up to and
including 2.0.36.
DAMAGE: Successful exploitation may lead to modified Web content,
denial of service, or further compromise.
SOLUTION: Users of Apache 1.3 should upgrade to 1.3.26, and users of
Apache 2.0 should upgrade to 2.0.39, which contains a fix for
this issue.
In particular, is the older version, Stronghold 2.4.2 which is built
on Apache 1.3.6 vulnerable? I notice that Apache 1.3.6 is earlier
than the versions of Apache cited in the CIAC bulletin. So perhaps
the older software is safe from the problem?
If Stronghold 2.4.2 is a problem, what fixes, if any are available?