Apache Web Server多个模块本地缓冲区溢出漏洞发布时间:2003-10-28 更新时间:2003-10-28 严重程度:中 威胁程度:权限提升 错误类型:边界检查错误 利用方式:服务器模式 BUGTRAQ ID:8911 受影响系统 Apache Software Foundation Apache 1.3未影响系统 Apache Software Foundation Apache 1.3.29详细描述 Apache存在一个漏洞,允许本地攻击者在主机上执行任意代码。问题是由于软件缺少正确的边界缓冲区检查,可触发缓冲区溢出。问题存在于mod_alias和mod_rewrite模块中。用户可以建立或修改配置文件触发此问题。 另外mod_cgid错误处理CGI重定向路径,可导致输出错误,把敏感信息转向给客户端,造成信息泄露。 解决方案 Apache Software Foundation Apache 1.3: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.1: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.3: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.4: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.6: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.9: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.11: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.12: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.14: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.17: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.18: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.19: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.20: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.22: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.23: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.24: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.25: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.26: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 1.3.27: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Immunix Upgrade apache-1.3.27-1.7.1_imnx_2.i386.rpm http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/apache-1.3.27-1.7.1_imnx_2.i386.rpm Immunix Upgrade apache-devel-1.3.27-1.7.1_imnx_2.i386.rpm http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/apache-devel-1.3.27-1.7.1_imnx_2.i386.rpm Immunix Upgrade apache-manual-1.3.27-1.7.1_imnx_2.i386.rpm http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/apache-manual-1.3.27-1.7.1_imnx_2.i386.rpm Apache Software Foundation Apache 1.3.28: Apache Software Foundation Upgrade apache_1.3.29.tar.gz http://apache.mirror.secondchapter.info/httpd/apache_1.3.29.tar.gz Apache Software Foundation Apache 2.0: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.28: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.32: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.35: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.36: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.37: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.38: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.39: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.40: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.41: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.42: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.43: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.44: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.45: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.46: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Apache Software Foundation Apache 2.0.47: Apache Software Foundation Upgrade httpd-2.0.48.tar.gz http://apache.sunsite.ualberta.ca/httpd/httpd-2.0.48.tar.gz Slackware Linux -current: Slackware Upgrade apache-1.3.29-i486-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/apache-1.3.29-i486-1.tgz Slackware Upgrade mod_ssl-2.8.16_1.3.29-i486-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/mod_ssl-2.8.16_1.3.29-i486-1.tgz Slackware Upgrade php-4.3.3-i486-3.tgz ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/php-4.3.3-i486-3.tgz Slackware Linux 8.1: Slackware Upgrade apache-1.3.29-i386-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/apache-1.3.29-i386-1.tgz Slackware Upgrade mod_ssl-2.8.16_1.3.29-i386-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/mod_ssl-2.8.16_1.3.29-i386-1.tgz Slackware Upgrade php-4.3.3-i386-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/packages/php-4.3.3-i386-1.tgz Slackware Linux 9.0: Slackware Upgrade apache-1.3.29-i386-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/apache-1.3.29-i386-1.tgz Slackware Upgrade mod_ssl-2.8.16_1.3.29-i386-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/mod_ssl-2.8.16_1.3.29-i386-1.tgz Slackware Upgrade php-4.3.3-i386-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-9.0/patches/packages/php-4.3.3-i386-1.tgz Slackware Linux 9.1: Slackware Upgrade apache-1.3.29-i486-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/apache-1.3.29-i486-1.tgz Slackware Upgrade mod_ssl-2.8.16_1.3.29-i486-1.tgz ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/mod_ssl-2.8.16_1.3.29-i486-1.tgz 相关信息 参考:http://www.apache.org/dist/httpd/CHANGES_2.0 |