Two security alerts point to Apache Web Server flaws
A patch for one of the flaws has been posted; a second patch should be available tonight.
June 17, 2002 12:00 PM ETComputerworld -
Two security alerts about new vulnerabilities affecting the popular open-source Apache Web Server were posted by two organizations today.
The nonprofit Apache HTTP Server Project group has issued a bulletin about a vulnerability that can allow distributed denial-of-service attacks in Apache Version 1.3, including 1.3.24, and Apache 2, including all versions up to 2.0.36.
The Apache Project said that an Internet Security Systems Inc. (ISS) patch posted earlier in the day for an Apache vulnerability doesn't fix the denial-of-service problem. A patch for that vulnerability is expected to be ready by tonight on the group's Web site.
In a separate posting, Atlanta-based security vendor ISS reported the discovery of a flaw in the Apache mechanism that calculates the size of "chunked" encoding for Windows 32-bit users. Chunked encoding is part of the HTTP specification used for accepting data from Web users, according to ISS.
When data is sent from the user, the Web server needs to allocate a memory buffer of a certain size to hold the submitted data. When the size of the data being submitted is unknown, the client or Web browser will communicate with the server by creating "chunks" of data of a negotiated size.
But the flaw, affecting Apache Versions 1.x, misinterprets the size of incoming data chunks, which could lead to a signal race, heap overflow and exploitation of malicious code, according to ISS.
ISS said it had posted a fix for the problem on its Web site.
Chris Rouland, director of ISS's X-Force research and development group, said the two vulnerabilities are different. The ISS patch will protect Windows servers running Apache from remote compromise attacks, he said, while the denial-of-service problem reported by the Apache Project appears to be a separate issue.
"This is open-source in action," he said, referring to the wide discourse on the exact vulnerabilities being addressed by both groups. "The value is you get a lot of different minds thinking about something, and the challenge is that you have to decide what to do."
Security
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
The State of PCI DSS Compliance at Organizations Today
Download this resource today!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Why Email Must Operate 24/7 and How to Make This Happen
Learn how to avoid an email outage by implementing a hosted email continuity solution.
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
