| 关键词: mod vulnerabilities apache 达人 deflate service Server denial proxy http |
问题存在于mod_proxy和mod_deflate,没POC,apache发了新版修复了,等达人diff写exp。 Problem Description: Multiple vulnerabilities has been found and corrected in apache: The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxymodule in the Apache HTTP Server before 2.3.3, when a reverse proxyis configured, does not properly handle an amount of streamed datathat exceeds the Content-Length value, which allows remote attackersto cause a denial of service (CPU consumption) via crafted requests(CVE-2009-1890). Fix a potential Denial-of-Service attack against mod_deflate or othermodules, by forcing the server to consume CPU time in compressing alarge file after a client disconnects (CVE-2009-1891). This update provides fixes for these vulnerabilities. |
|
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系
[邮箱地址] 删除
|