安全漏洞CN-VA04-40 发布日期:2004-6-11 漏洞影响:拒绝服务、远程系统访问 漏洞类型:边界溢出 漏洞评估:高危 受影响版本: Apache 1.3.31、1.3.29、1.3.28、1.3.27和1.3.26 漏洞描述: Georgi Guninski has discovered a vulnerability in Apache, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. The vulnerability is caused due to a boundary error within the Apache mod_proxy module. This can be exploited to cause a heap-based buffer overflow by passing a "Content-Length:" header containing a large negative value. Successful exploitation may reportedly crash the child process and potentially allow code execution on some BSD systems, if an Apache server, which is configured as a proxy, connects to a malicious site. 漏洞危害: 成功利用漏洞可能强行执行程序和SQL语句,将会对整个数据库和应用轻易地造成危害。 解决方案: The vulnerability has been fixed in version 1.3.32-dev. Disable mod_proxy. 参考信息: