You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@httpd.apache.org by Joe Orton <jo...@redhat.com> on 2011/11/03 15:21:48 UTC

[me@halfdog.net: Integer Overflow in Apache ap_pregsub via mod-setenvif]

----- Forwarded message from halfdog <me...@halfdog.net> -----

Date: Wed, 02 Nov 2011 11:55:26 +0000
From: halfdog <me...@halfdog.net>
To: full-disclosure@lists.grok.org.uk
CC: Joe Orton <jo...@apache.org>, security@httpd.apache.org
Subject: Integer Overflow in Apache ap_pregsub via mod-setenvif
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:10.0a1) Gecko/20111014 Firefox/10.0a1
	SeaMonkey/2.7a1

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

An exploitable integer overflow in apache allows to crash the apache
process or execution of arbitrary code as user running apache. To
exploit the vulnerability, a crafted .htaccess file has to be placed
on the server, therefore the vulnerability impact is rated "Low".

Micro-Advisory:
http://www.halfdog.net/Security/2011/ApacheModSetEnvIfIntegerOverflow/
CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3607

See advisory for more information about the vulnerability and (very
bad) example to execute arbitrary code, using racy code.

It should be possible to execute code without the need for a race
using crafted stop sequences, but I haven't managed to do it so far.
Perhaps someone else might take up the challenge.

hd

- -- 
http://www.halfdog.net/
PGP: 156A AE98 B91F 0114 FE88  2BD8 C459 9386 feed a bee
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAk6xLzAACgkQxFmThv7tq+7cfQCdHe9KhFPVQ0qx38+FQtR05aMG
iSAAnjJQ4pEJayrIs9Q62qxOsKsD+pLr
=AHBz
-----END PGP SIGNATURE-----

----- End forwarded message -----