RE: Apache HTTP Server Chunk Encoding Vulnerab ility

"Horner, Jonathan J. (JH8) " <[email protected]> Thu, 20 Jun 2002 16:16:43 -0400
Newsgroups gmane.linux.redhat.stronghold
Message-ID <[email protected]>
Along with my earlier post, both the ap_isxdigit and the ap_log_rerror
functions in the patch file are not in the older versions of Apache.  I
believe using isxdigit and ap_log_error should make the patch or just the
repairs work for older verions.  Note that Stronghold 2.2 is not able to be
fixed using this patch or any source code changes associated with it.

Thanks,

Jon Horner, CISSP
SAIC WebPool
[email protected]
Office:  (865) 425-5178
Pager:  (865) 417-5012


> -----Original Message-----
> From: marcus [mailto:[email protected]]
> Sent: Thursday, June 20, 2002 3:52 PM
> To: [email protected]
> Subject: Re: [Stronghold-users] Apache HTTP Server Chunk Encoding
> Vulnerability
> 
> 
> Raynard,
> 
> All versions of the Apache web server up to and
> including 1.3.24 are affected. Check out the official
> Apache advisory at: 
> 
> http://httpd.apache.org/info/security_bulletin_20020617.txt
> 
> to see it for yourself.
> 
> Get the Red Hat patch for Stronghold 3.0 from:
> 
> http://stronghold.redhat.com/sh3/errata-2002-118
> 
> and apply the patch to Stronghold 2.4.2 by hand
> yourself. I guess that's the only way since Stronghold
> 2.4.2 is no longer supported. Else upgrade to the
> latest version of Stronghold.
> 
> Marcus
> 
>  --- "Raynard A. Jong" <[email protected]> wrote: 
> > Are older versions of Stronghold also affected by
> > the Apache 
> > vulnerability recently announced by CIAC?
> > 
> > PROBLEM:       The Apache HTTP Server has a software
> > flaw that misinterprets
> >                 invalid requests encoded using
> > chunked encoding. This error can
> >                 be triggered remotely by sending
> > certain invalid requests.
> > PLATFORM:      Any systems running Apache web server
> > 1.3.24 and 2.0 up to and
> >                 including 2.0.36.
> > DAMAGE:        Successful exploitation may lead to
> > modified Web content,
> >                 denial of service, or further
> > compromise.
> > SOLUTION:      Users of Apache 1.3 should upgrade to
> > 1.3.26, and users of
> >                 Apache 2.0 should upgrade to 2.0.39,
> > which contains a fix for
> >                 this issue.
> > 
> > 
> > In particular, is the older version, Stronghold
> > 2.4.2 which is built 
> > on Apache 1.3.6  vulnerable?  I notice that Apache
> > 1.3.6 is earlier 
> > than the versions of Apache cited in the CIAC
> > bulletin.  So perhaps 
> > the older software is safe from the problem?
> > 
> > If Stronghold  2.4.2 is a problem, what fixes, if
> > any are available?
> 
> 
> __________________________________________________
> Do You Yahoo!?
> Everything you'll ever need on one web page
> from News and Sport to Email and Music Charts
> http://uk.my.yahoo.com
> 
> 
> 
> _______________________________________________
> Stronghold-users mailing list
> [email protected]
> https://listman.redhat.com/mailman/listinfo/stronghold-users
>