Another big Apache hole found
TechWorld.com - LONDON - Linux and Unix vendors are releasing fixes for a critical bug in the popular Web server Apache that could allow attackers to crash the system or execute malicious code.
The bug affects Apache 1.3.x installations configured to act as proxy servers, which relay requests between a Web browser and the Internet. When a vulnerable server connects to a malicious site, a specially crafted packet can be used to exploit the vulnerability, according to security researcher Georgi Guninski, who has publicly released exploit code.
The bug is most serious on BSD installations, where it may allow code execution, while on other platforms the most likely effect is a system crash, researchers said. A reference in the Common Vulnerabilities and Exposures database can be found here.
Guninski released information about the proxy-server bug earlier this month, and last month discovered a similar vulnerability in an Apache component offering Secure Sockets Layer encryption, but he said the bugs don't reflect on Apache's overall security relative to competitors such as Microsoft's Internet Information Services. "Still Apache is much better than Windows," he said in an advisory.
Debian released a patch for the bug today, and Gentoo Linux released its own patch last week. Red Hat Inc., OpenBSD and OpenPKG have also released updates fixing the bug, while Novell Inc.'s Suse Linux said in an advisory last week it is testing a patch. Researchers said Apple's BSD-based Mac OS X is likely affected, but Apple has not yet released a patch.
Apache versions 1.3.31, 1.3.29, 1.3.28, 1.3.27 and 1.3.26 are affected, while the bug has been fixed in 1.3.32-dev, according to security experts. System administrators can also get around the problem by switching off Apache's proxy-server module.
"If I were running a BSD system, I would be very careful with this," said Thomas Kristensen, CTO of Secunia, which maintains a database tracking vulnerability advisories. "It's important to note that the potential for code execution has not been proven to be exploitable, but it pays to be safe." BSD is frequently used by Web hosting companies, he said.
Kristensen said that despite the recent bugs, Apache's security is solid overall. Both Apache and IIS have been so thoroughly studied that few vulnerabilities are now discovered in their core components, he said - with both servers, problems are now mostly found in extensions such as mod_ssl and mod_proxy. "It's pretty solid as long as you remember to configure it correctly and to disable the extensions that are not necessary for your business," Kristensen said.
Thebug in Apache's mod_proxy module means that a negative user-specified length value may be used in a memory copy operation, leading to corruption of memory and a buffer overflow. The exploit can take effect when a remote server sends a negative Content-Length: HTTP header field to the proxy server.
The proxy bug is the sixth vulnerability in Apache 1.3.x reported this year, according to Secunia, which has recorded 10 such advisories in 2003 and 2004. Half of these were moderately or highly critical, usually meaning they allowed remote access to the system or denial of service. For comparison, IIS 5.x also had 10 advisories in the same period, 40% of which were highly or extremely critical, Secunia said.
In 2002, the Slapper worm took advantage of a month-old bug in Apache's mod_ssl component, causing widespread disruption.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Reducing the Cost and Complexity of Web Vulnerability Management
- Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.
Download this... - Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will... All Malware and Vulnerabilities White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Malware and Vulnerabilities Webcasts