LWN.net Logo

Apache 'chunk handling' vulnerability

Package(s):apache CVE #(s):CAN-2002-0392
Created:June 19, 2002 Updated:July 3, 2002
Description: It is past time to upgrade your Apache servers. A worm which takes advantage of the this vulnerability has been sighted, and its source has been publicly posted.

An apache httpd bug related to chunked encoding presents a denial of service vulnerability. For some platforms, including both 32-bit and 64-bit Linux, it is also a potential remote exploit vulnerability. A "carefully crafted invalid request" may be used to trigger the bug. The problem is fixed in Apache 2.0.39 and 1.3.26, which may be downloaded from here.

For more information, see the advisories from CERT and the Apache Group.

This vulnerability has been widely publicized. Applying a patch from your vendor or upgrading to the latest version from the Apache Software Foundation is strongly encouraged. Avoid patches from other sources; at least one patch that does not address the full scope of the problem has been circulated.

Alerts:
Trustix 2002-0058 2002-06-26
Red Hat RHSA-2002:117-11 2002-06-26
Yellow Dog YDU-20020626-1 2002-06-26
Mandrake MDKSA-2002:039-2 2002-06-20
SCO Group CSSA-2002-029.0 2002-06-20
Debian DSA-133-1 2002-06-20
Mandrake MDKSA-2002:039 2002-06-20
Red Hat RHSA-2002:118-06 2002-06-20
Trustix 2002-0056 2002-06-19
Slackware sl-1024577820 2002-06-20
Red Hat RHSA-2002:103-13 2002-06-19
Eridani ERISA-2002:024 2002-06-19
Gentoo Apache-20020619 2002-06-19
Conectiva CLA-2002:498 2002-06-19
OpenPKG OpenPKG-SA-2002.004 2002-06-19
SuSE SuSE-SA:2002:022 2002-06-18
Debian DSA-131-1 2002-06-19
Debian DSA-131-2 2002-06-19
Debian DSA-132-1 2002-06-19
EnGarde ESA-20020619-014 2002-06-19

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds