Full Disclosure mailing list archives
Integer Overflow in Apache ap_pregsub via mod-setenvif
From: halfdog <me () halfdog net>
Date: Wed, 02 Nov 2011 11:55:26 +0000
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 An exploitable integer overflow in apache allows to crash the apache process or execution of arbitrary code as user running apache. To exploit the vulnerability, a crafted .htaccess file has to be placed on the server, therefore the vulnerability impact is rated "Low". Micro-Advisory: http://www.halfdog.net/Security/2011/ApacheModSetEnvIfIntegerOverflow/ CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3607 See advisory for more information about the vulnerability and (very bad) example to execute arbitrary code, using racy code. It should be possible to execute code without the need for a race using crafted stop sequences, but I haven't managed to do it so far. Perhaps someone else might take up the challenge. hd - -- http://www.halfdog.net/ PGP: 156A AE98 B91F 0114 FE88 2BD8 C459 9386 feed a bee -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAk6xLzAACgkQxFmThv7tq+7cfQCdHe9KhFPVQ0qx38+FQtR05aMG iSAAnjJQ4pEJayrIs9Q62qxOsKsD+pLr =AHBz -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Integer Overflow in Apache ap_pregsub via mod-setenvif halfdog (Nov 02)