Lucene search

K
saintSAINT CorporationSAINT:CE48F764F3535D6A2E3CBFC45B9F2609
HistoryMay 08, 2006 - 12:00 a.m.

Apache chunked encoding buffer overflow

2006-05-0800:00:00
SAINT Corporation
my.saintcorporation.com
172

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.753

Percentile

98.2%

Added: 05/08/2006
CVE: CVE-2002-0392
BID: 5033
OSVDB: 838

Background

Apache web servers support chunked encoding, which is used by a web client to send data to the server in parts, or chunks.

Problem

A flaw in the calculation of the size of chunked encoding leads to a buffer overflow, allowing remote command execution.

Resolution

Upgrade to the latest version of Apache.

References

<http://www.cert.org/advisories/CA-2002-17.html&gt;

Limitations

Due to the nature of this vulnerability, this exploit may not always be reliable.

Platforms

Windows

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.753

Percentile

98.2%