(HP Issues Fix for HP-UX/Virtualvault) Apache Chunked Transfer-Encoding and Content-Length Processing Lets Remote Users Smuggle HTTP Requests
|
|
SecurityTracker Alert ID: 1015783 |
|
SecurityTracker URL: http://securitytracker.com/id/1015783
|
|
CVE Reference:
CVE-2005-2088
(Links to External Site)
|
Date: Mar 17 2006
|
Impact:
Modification of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
|
Description:
A vulnerability was reported in the Apache web server. A remote user may be able to conduct HTTP request smuggling attacks against web-based applications on the target system.
A remote user can submit a specially crafted request with both a 'Transfer-Encoding: chunked' header and a 'Content-Length' header to cause Apache to forward the reassembled request with the original Content-Length HTTP header value. As a result, a malicious request may be embedded within another request as processed by the subsequent application (such as an application server or a proxied system).
This vulnerability was reported by Watchfire.
A description of HTTP request smuggling attacks is available at:
http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf
|
Impact:
A remote user may be able to cause Apache to reassemble a connection in such a way that an application (such as an application server) to incorrectly process the connection.
|
Solution:
HP has issued the following fixes for HP-UX B.11.04 running Virtualvault, available at:
http://itrc.hp.com
PHSS_34169 Virtualvault 4.7 IWS update
PHSS_34121 Virtualvault 4.7 OWS (Apache 1.x) update
PHSS_34170 Virtualvault 4.6 IWS update
PHSS_34120 Virtualvault 4.6 OWS update
PHSS_34171 Virtualvault 4.5 IWS update
PHSS_34119 Virtualvault 4.5 OWS update
PHSS_34203 Webproxy server 2.1 (Apache 1.x) update
PHSS_34204 Webproxy server 2.0 update
The HP advisory is available at:
http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828
|
Vendor URL: httpd.apache.org/ (Links to External Site)
|
Cause:
State error
|
Underlying OS:
UNIX (HP/UX)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Fri, 17 Mar 2006 15:04:13 -0500
Subject: HPSBUX02101 SSRT051128 rev.1 - HP-UX VirtualVault running Apache 1.3.X Remote Unauthorized Access
|
http://www2.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828
|
|