Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:APACHE:MASSACRE-DOS-VAR

Severity

Major

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Apache Massacre Denial of Service Variant

Release Date

2003/06/18

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Apache Massacre Denial of Service Variant


This signature detects attempts to exploit a memory leak in Apache Web server. Windows and Unix implementations of Apache Web server prior to version 2.0.45 are vulnerable. Attackers can include thousands of carriage returns and linefeeds in a request to crash the Apache server.

Extended Description

Apache 2.0 series webservers are prone to a denial-of-service condition. This issue occurs because of the way that Apache handles excessive amounts of consecutive linefeed characters. The server may allocate large amounts of memory, resulting in a denial of service.

Affected Products

  • Apache_software_foundation apache 2.0.0
  • Apache_software_foundation apache 2.0.0 A9
  • Apache_software_foundation apache 2.0.28
  • Apache_software_foundation apache 2.0.32
  • Apache_software_foundation apache 2.0.35
  • Apache_software_foundation apache 2.0.36
  • Apache_software_foundation apache 2.0.37
  • Apache_software_foundation apache 2.0.38
  • Apache_software_foundation apache 2.0.39
  • Apache_software_foundation apache 2.0.40
  • Apache_software_foundation apache 2.0.41
  • Apache_software_foundation apache 2.0.42
  • Apache_software_foundation apache 2.0.43
  • Apache_software_foundation apache 2.0.44
  • Apple mac_os_x_server 10.2.0
  • Apple mac_os_x_server 10.2.1
  • Apple mac_os_x_server 10.2.2
  • Apple mac_os_x_server 10.2.3
  • Apple mac_os_x_server 10.2.4
  • Computer_associates arcserve_backup_for_aix 11.5
  • Computer_associates arcserve_backup_for_solaris 11.5
  • Computer_associates arcserve_backup_for_tru64 11.5
  • Computer_associates brightstor_arcserve_backup_for_hp 11.1.0
  • Hp apache-based_web_server 2.0.43 .00
  • Hp apache-based_web_server 2.0.43 .04
  • Hp hp-ux_apache-based_web_server 1.0.0 .01
  • Hp hp-ux_apache-based_web_server 1.0.0 .02.01
  • Hp hp-ux_apache-based_web_server 1.0.1 .01

References

  • BugTraq: 7254
  • CVE: CVE-2003-0132
  • URL: http://www.redhat.com/support/errata/RHSA-2003-139.html
  • URL: http://oval.mitre.org/oval/definitions/data/oval156.html
  • URL: http://www.kb.cert.org/vuls/id/206537

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out