Slashdot Mirror


Apache Vulnerability Announced

Aaron writes "Versions of the Apache HTTP Server up to and including 1.3.24 and 2.0 up to and including 2.0.36 contain a bug in the routines which deal with invalid requests which are encoded using chunked encoding. In some cases it may be possible to cause a child process to terminate and restart, which consumes a non-trivial amount of resources. See the official announcement and stay tuned here for updated versions." This is in response to the rather uninformed and questionable security notice by ISS X-Force, about a bug that has already been mentioned on the public mailing lists for Apache and is fixed in CVS for Apache 2.0. I am also told that their patch doesn't fully solve the problem. I am sure though that by awaking us to the problem they will get a lot of great press just like any of the other companies currently using useless bug announcements as press releases.

10 of 296 comments (clear)

  1. Arrrgggh my fucking eyes! by Anonymous Coward · · Score: -1, Offtopic

    Im blind from the purple and piss color color scheme found on this page.

  2. IIS r0x0rs! by gerf · · Score: -1, Offtopic

    W is for windows

    it's good enough for me

    W is for windows

    it's good enough for me

    w is for windows

    cause i'm a big dummie!

  3. Here's some holes I'd like to exploit... by Anonymous Coward · · Score: -1, Offtopic

    GOOOAAALLL!

    (Brazil Women's Soccer Team!!)

    1. Re:Here's some holes I'd like to exploit... by Anonymous Coward · · Score: -1, Offtopic

      (Brazil Women's Soccer Team!!)

      Yeah, right. Don't believe everything you read in pr0n mags (and nowhere is it said that this is the Brazilian team).
      Women football players are lesbian of course, but they're BUTCHES, not the models you're seeing on that page. Come on.

  4. A complaint! by Anonymous Coward · · Score: -1, Offtopic

    norrog@linux:~> cat complaint.troll
    The ADS on $la$hdot and the O$DN ANNOY ME.

    Ones that annoyme most,
    $hit forge adverts, no one want's to risk developing critcal applications
    with you so fuck off!

    AnimeFu/Megatokyo adverts! Japanime sucks, so does slashdot!

    Microsoft Visual Studio .net adverts! Why the FUCK are you letting the
    devil advertise with you. Oh now I remember, open sores have no way to
    make money so they ask big companies to support them!

    Conclusion. Don't tolerate it! Don't subscribe to $la$hdot. Instead go
    and install Junk buster [junkbuster.com] and say no to shitty adverts! The
    ones found here are worser than the pr0n sites!

  5. Important - Need Gook / Geek porn by Anonymous Coward · · Score: -1, Offtopic

    Does anyone have any pornographic pictures of Mae Ling Mak that I could use for masturbation please?

    1. Re:Important - Need Gook / Geek porn by Grape+Smuggler · · Score: -1, Offtopic


      http://spinster.org/my_photos/

      Damn, she is an ugly woman. If you can masturbate to that, more power to ya.

  6. Re:Enough Already by SealBeater · · Score: 2, Offtopic

    It's pretty funny that you say that. From the email


    X-Force has verified that this issue is exploitable on Apache for
    Windows (Win32) version 1.3.24. Apache 1.x for Unix contains the same
    source code, but X-Force believes that successful exploitation on most
    Unix platforms is unlikely.


    and

    From Apache.org:
    In Apache 1.3 the issue causes a stack overflow. Due to the nature of the
    overflow on 32-bit Unix platforms this will cause a segmentation violation
    and the child will terminate. However on 64-bit platforms the overflow
    can be controlled and so for platforms that store return addresses on the
    stack it is likely that it is further exploitable. This could allow
    arbitrary code to be run on the server as the user the Apache children are
    set to run as.

    We have been made aware that Apache 1.3 on Windows is exploitable in this
    way.


    Now, what were you saying about Windows vs. *nix?

    SealBeater

    --
    -- Its survival of the fittest...and we got the fucking guns!!!
  7. Re:slashdot.org should be renamed spinroom.org by msaavedra · · Score: 2, Offtopic

    Because of you're low ID, I assume you are not a troll, but you seem to have some misconceptions about this. This is not a linux bug, it is an apache bug. No 32-bit unixes will get rooted as a result of this, though a DoS is possible. Windows and 64-bit unixes could be vulnerable to a serious exploit, if apache is running as a privileged user, is not chroot'ed, etc. I think most 64-bit unix admins will be able to manage the problem until a good patch is available. One can only hope that there aren't too many people running apache on windows.

    --
    "Any fool can make a rule, and any fool will mind it."
    --Henry David Thoreau
  8. International Sandwich Shop by Anonymous Coward · · Score: -1, Offtopic

    uuummmmmm, a 16" Roast Beef after a night of binge drinking sounds really good right now. Both the sandwich and binge drinking.

    I miss school so much some days, as I sit and work on useless, uninteresting projects. At least school had useless, interesting projects to work on.

    At any rate, all this mentioning of ISS is making me hungry.