vendor:
http_server
by:
patrick
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: http_server
Affected Version From: 1.3.29
Affected Version To: 2.2.2002
Patch Exists: YES
Related CWE: CVE-2006-3747
CPE: a:apache:http_server
Metasploit:
https://www.rapid7.com/db/vulnerabilities/apache-httpd-2_2_x-mod_rewrite-off-by-one-error-cve-2006-3747/, https://www.rapid7.com/db/vulnerabilities/http-apache-mod-rewrite-bof/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-1_3_x-mod_rewrite-off-by-one-error-cve-2006-3747/, https://www.rapid7.com/db/vulnerabilities/hpsmh-cve-2006-3747/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apache-cve-2006-3747/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-cve-2006-3747/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2006-3747/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-dc8c08c7-1e7c-11db-88cf-000c6ec775d9/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2006-3747/
Platforms Tested: Windows
2010
Apache module mod_rewrite LDAP protocol Buffer Overflow
This module exploits the mod_rewrite LDAP protocol scheme handling flaw discovered by Mark Dowd, which produces an off-by-one overflow. Apache versions 1.3.29-36, 2.0.47-58, and 2.2.1-2 are vulnerable. This module requires REWRITEPATH to be set accurately. In addition, the target must have 'RewriteEngine on' configured, with a specific 'RewriteRule' condition enabled to allow for exploitation. The flaw affects multiple platforms, however this module currently only supports Windows based installations.
Mitigation:
Apply the vendor patches to fix the vulnerability.