Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability
Published on 2006-08-01. Updated on 2007-04-17.
Description:
This alert was generated using only banner information. It may be a false positive.
Apache mod_rewrite is prone to an off-by-one buffer-overflow condition. The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.
Affected Apache versions:
- Apache 1.3.28 - 1.3.36 with mod_rewrite
- Apache 2.2.0 - 2.2.2 with mod_rewrite
- Apache 2.0.46 - 2.0.58 with mod_rewrite
Impact:
An attacker may exploit this issue to trigger a denial-of-service condition. Reportedly, arbitrary code execution may also be possible.
Recommendation:
Upgrade Apache to the latest version.
Alert Tags: configuration
ApplicableApplicationServer : All
ApplicableOS: All
ApplicableWebServer: Apache
References:
Go Back