首页 网络安全 安全学院 查看内容

apache两个dos漏洞

2009-7-11 11:20 675 0

摘要: 问题存在于mod_proxy和mod_deflate,没POC,apache发了新版修复了,等达人diff写exp。 Problem Description: Multiple vulnera...
关键词: mod vulnerabilities apache 达人 deflate service Server denial proxy http

问题存在于mod_proxy和mod_deflate,没POC,apache发了新版修复了,等达人diff写exp。 Problem Description: Multiple vulnerabilities has been found and corrected in apache: The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxymodule in the Apache HTTP Server before 2.3.3, when a reverse proxyis configured, does not properly handle an amount of streamed datathat exceeds the Content-Length value, which allows remote attackersto cause a denial of service (CPU consumption) via crafted requests(CVE-2009-1890). Fix a potential Denial-of-Service attack against mod_deflate or othermodules, by forcing the server to consume CPU time in compressing alarge file after a client disconnects (CVE-2009-1891). This update provides fixes for these vulnerabilities.
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

最新评论

返回顶部