Lucene search

K
kasperskyKaspersky LabKLA10066
HistoryOct 19, 2010 - 12:00 a.m.

KLA10066 Multiple vulnerabilities in Apache httpd

2010-10-1900:00:00
Kaspersky Lab
threats.kaspersky.com
121

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.3 High

AI Score

Confidence

High

0.973 High

EPSS

Percentile

99.9%

Multiple serious vulnerabilities have been found in Apache httpd. Malicious users can exploit these vulnerabilities to cause denial of service, obtain sensitive information, inject code or execute arbitrary code. Below is a complete list of vulnerabilities

  1. Multiple integer overflow vulnerabilities can be exploited remotely via vectors related to Apache Portable Runtime;
  2. Vectors related to Expat 2.0.1 can be exploited by a specially designed XML document;
  3. An XSS vulnerability can be exploited remotely via specially a designed FTP URI
  4. Vectors related to mod_proxy_ftp can be exploited remotely via a specially designed reply to an EPSV command or specially formed HTTP headers;
  5. An improper work with forwarded interim responses vulnerability can be exploited remotely via a large number of interim responses;
  6. An improper compression vulnerability can be exploited by remote attackers via connection manipulation;
  7. Vectors related to mod_cache and mod_dav can be exploited remotely via a specially designed request;
  8. An improper mod_isapi unload can be exploited remotely via vectors related to request, request packed and callback points;
  9. A memory leak vulnerability can be exploited remotely via vectors related to the APR bucket;
  10. An improper headers handling vulnerability can be exploited remotely via a specially designed request.

Original advisories

Apache changelog

Related products

Apache-HTTP-Server

CVE list

CVE-2010-1452 critical

CVE-2009-2412 critical

CVE-2009-3720 critical

CVE-2008-2939 warning

CVE-2009-3094 warning

CVE-2008-2364 critical

CVE-2009-1891 high

CVE-2009-3560 critical

CVE-2010-1623 critical

CVE-2010-0425 critical

CVE-2009-3095 critical

CVE-2010-0434 warning

Solution

Update to latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • CI

Code injection. Exploitation of vulnerabilities with this impact can lead to changes in target code.

Affected Products

  • Apache httpd 2.0 versions 2.0.63 and earlier

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.3 High

AI Score

Confidence

High

0.973 High

EPSS

Percentile

99.9%