SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Web Server/CGI)  >   Apache Vendors:   Apache Software Foundation
Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon
SecurityTracker Alert ID:  1009337
SecurityTracker URL:  http://securitytracker.com/id/1009337
CVE Reference:   CAN-2004-0113   (Links to External Site)
Date:  Mar 8 2004
Impact:   Denial of service via network
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  
Version(s): 2.0.35 through 2.0.48
Description:   A vulnerability was reported in Apache mod_ssl. A remote user may be able to deny service.

It is reported that a remote user can send plain HTTP requests to the SSL port on an SSL-enabled Apache web server to cause denial of service conditions. The vulnerability is due to a memory leak in mod_ssl, the report said.

The flaw reportedly resides in the ssl_io_filter_disable() function in the 'ssl_engine_io.c' file.

Versions 2.0.35 through 2.0.48 are reportedly affected.

Mick Wall is credited with reporting this vulnerability.

Impact:   A remote user can cause the web service to crash.
Solution:   A fixed version (2.0.49-dev) is available at:

http://httpd.apache.org/

A fix is also available via CVS at:

http://cvs.apache.org/viewcvs.cgi/httpd-2.0/modules/ssl/ssl_engine_io.c?r1=1.117&r2=1.118

Vendor URL:  nagoya.apache.org/bugzilla/show_bug.cgi?id=27106 (Links to External Site)
Cause:   Resource error
Underlying OS:   Linux (Any), UNIX (Any), Windows (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Mar 24 2004 (Red Hat Issues Fix for RH Enterprise Linux) Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Enterprise Linux 3.
Apr 1 2004 (Trustix Issues Fix) Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon   (Trustix Security Advisor <tsl@trustix.org>)
Trustix has released a fix.
Apr 14 2004 (Conectiva Issues Fix) Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon   (Conectiva Updates <secure@conectiva.com.br>)
Conectiva has released a fix.
Apr 26 2004 (HP Issues Fix for HP-UX) Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon
HP has issued a fix for HP-UX.
Apr 30 2004 (Red Hat Issues Fix for RH Linux) Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon   (bugzilla@redhat.com)
Red Hat has released a fix for Red Hat Linux 9.
May 4 2004 (Apple Issues Fix for OS X) Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon   (Apple Product Security <product-security@apple.com>)
Apple has released a fix for Mac OS X.
May 11 2004 (Mandrake Issues Fix) Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon   (Mandrake Linux Security Team <security@linux-mandrake.com>)
Mandrake has released a fix.
May 25 2004 (Fedora Issues Fix) Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon   (Joe Orton <jorton@redhat.com>)
Fedora has released a fix for Fedora Core 1 (FC1).
Jun 11 2004 (HP Issues Fix for Tru64) Apache mod_ssl Memory Leak Lets Remote Users Crash the Daemon
HP has issued patches.



 Source Message Contents

Date:  Mon, 08 Mar 2004 08:12:55 -0500
Subject:  CAN-2004-0113


 > Fixed in Apache httpd 2.0.49-dev

 > mod_ssl memory leak CAN-2004-0113

 > A memory leak in mod_ssl allows a remote denial of service attack against
 > an SSL-enabled server by sending plain HTTP requests to the SSL port.

Versions 2.0.35 through 2.0.48 are reportedly affected.

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC