Apache mod_proxy模块HTTP分块编码整数溢出漏洞

admin 2022-07-12 16:59:55 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

Apache mod_proxy模块HTTP分块编码整数溢出漏洞

  • CNNVD编号:CNNVD-201002-005
  • 危害等级: 中危
  • CVE编号: CVE-2010-0010
  • 漏洞类型: 数字错误
  • 发布时间: 2010-01-27
  • 威胁类型: 远程
  • 更新时间: 2021-06-07
  • 厂        商: apache
  • 漏洞来源: Adam Zabrocki※ pi3...

漏洞简介

Apache HTTP Server是一款流行的Web服务器。

Apache服务器的mod_proxy模块在64位操作系统中存在堆栈溢出漏洞,允许远程原服务器引起拒绝服务攻击或可能执行任意代码利用一个大块的数据引起堆栈溢出。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Apache Software Foundation Apache 1.3.35

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.34

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.34

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.40-dev

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.1

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.11

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.11

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.12

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.12

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.13

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.14

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.14

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.14 Mac

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.15

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.16

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.17

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.17

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.18

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.18

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.19

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.19

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.20

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.20

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.22

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.22

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.tar.gz

Apache Software Foundation Apache 1.3.23

Apache Software Foundation apache_1.3.42.tar.gz

http://httpd.apache.org/dev/dist/apache_1.3.42.

参考网址

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/1001

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7923

来源:httpd.apache.org%3E

链接:httpd.apache.org%3E

来源:MLIST

链接:https://lists.apache.org/thread.HTML/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e@%3Ccvs.

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0240

来源:MISC

链接:http://blog.pi3.com.pl/?p=69

来源:MLIST

链接:https://lists.apache.org/thread.HTML/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.

来源:MISC

链接:http://site.pi3.com.pl/adv/mod_proxy.txt

来源:BUGTRAQ

链接:http://www.securityfocus.com/archive/1/509185/100/0/threaded

来源:FULLDISC

链接:http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0589.HTML

来源:httpd.apache.org

链接:httpd.apache.org/dev/dist/CHANGES_1.3.42

来源:MLIST

链接:https://lists.apache.org/thread.HTML/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e@%3Ccvs.

来源:MISC

链接:http://packetstormsecurity.org/1001-exploits/modproxy-overflow.txt

来源:MLIST

链接:https://lists.apache.org/thread.HTML/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.

来源:SECUNIA

链接:http://secunia.com/advisories/38319

来源:BID

链接:https://www.securityfocus.com/bid/37966

来源:MLIST

链接:https://lists.apache.org/thread.HTML/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7@%3Ccvs.

来源:HP

链接:http://marc.info/?l=bugtraq&m=130497311408250&w=2

来源:SECUNIA

链接:http://secunia.com/advisories/39656

来源:XF

链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/55941

来源:SECTRACK

链接:http://www.securitytracker.com/id?1023533

来源:MLIST

链接:https://lists.apache.org/thread.HTML/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d@%3Ccvs.

来源:SUSE

链接:http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.HTML

来源:MLIST

链接:https://lists.apache.org/thread.HTML/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5@%3Ccvs.

受影响实体

  • Apache Http_server:0.8.11  
  • Apache Http_server:0.8.14  
  • Apache Http_server:1.0  
  • Apache Http_server:1.0.5  
  • Apache Http_server:1.0.3  

补丁

  • apache_1.3.42.tar
  • apache_1.3.42.tar
  • apache_1.3.42.tar

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
评论:0   参与:  0