Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:APACHE:APR-UTIL-LIB-DOS

Severity

Minor

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Apache apr-util IPv6 URI Parsing Denial of Service

Release Date

2012/11/26

Update Number

2205

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Apache apr-util IPv6 URI Parsing Denial of Service


This signature detects attempts to exploit a known vulnerability against Apache web server version 2.0.50 and earlier. A successful attack can lead to denial of service.

Extended Description

The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.

Affected Products

  • Apache http_server 2.0
  • Apache http_server 2.0.28
  • Apache http_server 2.0.32
  • Apache http_server 2.0.35
  • Apache http_server 2.0.36
  • Apache http_server 2.0.37
  • Apache http_server 2.0.38
  • Apache http_server 2.0.39
  • Apache http_server 2.0.40
  • Apache http_server 2.0.41
  • Apache http_server 2.0.42
  • Apache http_server 2.0.43
  • Apache http_server 2.0.44
  • Apache http_server 2.0.45
  • Apache http_server 2.0.46
  • Apache http_server 2.0.47
  • Apache http_server 2.0.48
  • Apache http_server 2.0.49
  • Apache http_server 2.0.50

References

  • CVE: CVE-2004-0786

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out