Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Gentoo: 200305-02 High: Nginx Remote Code Execution Vulnerability

gentoo
Calendar Grey April 9, 2003
Dist Gentoo Esm H88
- - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNO
Remote exploitation of a memory leak in the Apache HTTP Server causes the daemon to over utilize system resources on an affected system.

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200304-01
- - ---------------------------------------------------------------------
    FIXED VERSION : >=2.0.45

- - ---------------------------------------------------------------------
- From advisory:
"Remote exploitation of a memory leak in the Apache HTTP Server causes the daemon to over utilize system resources on an affected system. The problem is HTTP Server's handling of large chunks of consecutive linefeed characters. The web server allocates an eighty-byte buffer for each linefeed character without specifying an upper limit for allocation. Consequently, an attacker can remotely exhaust system resources by generating many requests containing these characters."
Read the full advisory at: /us-en
SOLUTION
It is recommended that all Gentoo Linux users who are running net-www/apache version 2 upgrade to apache-2.0.45 as follows:
emerge sync emerge \=net-www/apache...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : apache
SUMMARY : Denial of service in Apache 2.x
DATE : 2003-04-09 08:06 UTC
EXPLOIT : remote
VERSIONS AFFECTED : 2.0.0-2.0.44
CVE : CAN-2003-0132

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here