HZNQ.COM
welcome to my space
X
Article search:  
Welcome to:hznq.com
NAVIGATION - HOME
Apache Buffer Overflow Flaw Patched
Published by: webmaster 2008-08-30

The Apache Software Foundation has rolled out a patch for versions of its popular Apache HTTP Server to fix a potentially serious security flaw.

The buffer overflow flaw affects Apache httpd versions 1.3.26, 1.3.27, 1.3.28, 1.3.29 and 1.3.31, which were configured to act as proxy servers. Apache httpd 2.0 and other versions of Apache httpd 1.3 are unaffected.

BetaNews | MySQL Patches Security Flaws::
by FrSIRT, one of the flaws involves a buffer overflow that could allow for You dont need to change your apache setup.
http://www.betanews.com/article/MySQL_Patches_Security_Flaws/1146765359
HOME

An Apache Week advisory said the buffer overflow can be triggered by getting the mod_proxy feature to connect to a remote server and return an invalid content-length.

The vulnerability is rated "important," but the advisory warned that there is the possibility that it could be exploited to run arbitrary code.

"If you are running an Apache Web server, we'd recommend that you take a look at your configuration files and make sure that you have not inadvertently set up an open proxy. If you do not need your server to act as a proxy server, then make sure that the directive "ProxyRequests On" does not appear in your configuration file," Apache said.

SecuriTeam - Apache mod_rewrite LDAP URI Handling Remote Off-By-One ::
Apache mod_rewrite LDAP URI Handling Remote Off-By-One Buffer flaw is due to an off-by-one buffer overflow in Fully Patched Vim
http://www.securiteam.com/securitynews/5OP0W0AJ5Y.html
HOME

The risk of code execution is high on older OpenBSD/FreeBSD distributions because of the internal implementation of memcpy, which re-reads the length value from the stack. On newer BSD distributions, it may be exploitable because the implementation of memcpy will write three arbitrary bytes to an attacker-controlled location, according to the alert.

Linux and UNIX vendors, including Gentoo Linux, OpenBSD, Debian and Red Hat, have all issued updates to protect against the Apache Server bug.




Pre-Article:Spyware Sneaking into the Enterprise
Next-Article:US-CERT: Beware of IE
  • Industry Gears up for Telecom Tradeshow
  • Study Shows Security Market Doubling By 2006
  • Web Traffic Spikes After London Bombing
  • Chips and Dips
  • Computer Crime And The Bottom Line
  • Securities Industry IT Spend to Hit $71.5 Billion
  • Intel Takes 'Proactive' Approach to R&D
  • AMD's Hammer, Transmeta's TM6000 Chips
  • Server Sales Fall But Shipments Climb
  • Forbes.com in Content Deal with Yahoo!
  • Loyalty Points Arrive at eBay
  • The Great Credit Card Bazaar
  • Coming Soon ... the Outernet
  • Valu-Net, AOL Canada Sign Marketing Deal
  • As IT Budgets Inch Up, So Do Expectations
  • T-Mobile Investigating Alleged Hacker
  • Nortel's Virtual Trade Show
  • CSC Snags $735M Outsourcing Deal
  • InfoXpress.Com to Build Buyer's Guides for Digital Media Net
  • Priceline Adds New Airline Partners
  • MP3.com Settles Suits with Warner, BMG
  • The Bottom Line of Offshore Development
  • Storage Computer Signs Distributor Agreement With Pan-European Group
  • Vendors Set Sights on Server Standards
  • The Baan Company Chooses BroadVision
  • ITXC Gets Vo-IP Call Management Patent
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info aboutApache Buffer Overflow Flaw Patched, Please add it free.
     Homepage | Add to favorites | Contact us | Exchange links | LOGIN | Site map | 
    Copyright© 2008 hznq.com        Site made:CFZ