Apache mod_rewrite off-by-one buffer overflow vulnerability

Description
  • <div class="bb-coolbox"><span class="bb-dark">This alert was generated using only banner information. It may be a false positive. </span></div> <br/>Apache mod_rewrite is prone to an off-by-one buffer-overflow condition. The vulnerability arising in the mod_rewrite module's ldap scheme handling allows for potential memory corruption when an attacker exploits certain rewrite rules.<br/><br/> <span class="bb-navy">Affected Apache versions: <ul><li>Apache 1.3.28 - 1.3.36 with mod_rewrite</li> <li>Apache 2.2.0 - 2.2.2 with mod_rewrite</li> <li>Apache 2.0.46 - 2.0.58 with mod_rewrite</li></ul> </span><br/>
Remediation
  • Upgrade Apache to the latest version.
References