首页 > 技术点滴 > apache两个dos漏洞

apache两个dos漏洞

2009年7月10日 baoz 阅读评论

问题存在于mod_proxy和mod_deflate,没POC,apache发了新版修复了,等达人diff写exp。

Problem Description:

Multiple vulnerabilities has been found and corrected in apache:

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy
module in the Apache HTTP Server before 2.3.3, when a reverse proxy
is configured, does not properly handle an amount of streamed data
that exceeds the Content-Length value, which allows remote attackers
to cause a denial of service (CPU consumption) via crafted requests
(CVE-2009-1890).

Fix a potential Denial-of-Service attack against mod_deflate or other
modules, by forcing the server to consume CPU time in compressing a
large file after a client disconnects (CVE-2009-1891).

This update provides fixes for these vulnerabilities.

包子猜您可能还喜欢下列文章:

  1. MS08-073修复了4个IE 0day
  2. 当网管软件可以remote exec–HP OpenView
  3. vmware vSphere 4.0 Update 1
  4. 利用freebsd-update升级freebsd zz
  5. stack cookie,are you ready ?

分类: 技术点滴 标签:
  1. 本文目前尚无任何评论.
What is 8 + 13 ?
Please leave these two fields as-is:
请回答一个简单的问题避免垃圾评论