|
 |
|
IBM HTTP Server PCRE and Byte-Range Filter Vulnerabilities
|
|
|
|
|
Secunia Advisory:
|
SA17036
|
|
|
Release Date:
|
2005-10-07
|
|
Last Update:
|
2007-07-27
|
|
|
Critical:
|

Moderately critical
|
|
Impact:
|
Privilege escalation DoS
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | IBM HTTP Server 2.x IBM Rational ClearQuest 6.x IBM Rational ClearQuest 7.x IBM Websphere Application Server 4.x IBM WebSphere Application Server 5.x IBM WebSphere Application Server 6.0.x
|
| | CVE reference: | CVE-2005-2491 (Secunia mirror) CVE-2005-2728 (Secunia mirror) CVE-2005-2970 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: IBM has acknowledged two vulnerabilities in IBM HTTP Server, which can be exploited by malicious people to cause a DoS (Denial of Service), or by malicious, local users to gain escalated privileges via a specially crafted ".htaccess" file.
For more information:
SA16688
SA16559
The vulnerabilities have been reported in versions 2.0.42.2, 2.0.47, and 2.0.47.1.
NOTE: IBM HTTP Server is bundled with IBM WebSphere Application Server and IBM Rational ClearQuest.
A memory leak in worker.c when an accept() fails has also been fixed.
Solution: -- IBM HTTP Server Version 2.0.42.2, 2.0.47, and 2.0.47.1 --
Install temporary e-fix.
ftp://ftp.software.ibm.com/software/websphere/ihs/support/fixes/PK13230/
2235690824 5427200 2.0.42.2-PK13230.aix.tar
939210679 19537920 2.0.42.2-PK13230.hpux.tar
854827529 4474880 2.0.42.2-PK13230.linux.tar
3035375644 4904960 2.0.42.2-PK13230.linux390.tar
218954935 6502400 2.0.42.2-PK13230.linuxppc.tar
2142785978 3932767 2.0.42.2-PK13230.nt.zip
3619888137 18137088 2.0.42.2-PK13230.sun.tar
1195706654 5304320 2.0.47.1-PK13230.aix.tar
3981623684 19752960 2.0.47.1-PK13230.hpux.tar
1282754306 4106240 2.0.47.1-PK13230.linux.tar
920133865 4874240 2.0.47.1-PK13230.linux390.tar
844387247 5683200 2.0.47.1-PK13230.linuxppc.tar
3545755713 4019142 2.0.47.1-PK13230.nt.zip
508704124 17763328 2.0.47.1-PK13230.sun.tar
-- IBM HTTP Server included with WebSphere Application Server 6 --
Apply Fix Pack 3 (requires Version 6.0.2).
AIX Platforms:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24010719
Solaris Platforms:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24010723
Linux Platforms:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24010722
Windows Platforms:
http://www-1.ibm.com/support/docview.wss?rs=0&uid=swg24010724
-- IBM HTTP Server included with Rational ClearQuest --
Fixed in IBM_HTTP_Server/6.0.2.13 Apache/2.0.47 that is included in ClearQuest 7.0.1 release.
Changelog: 2005-10-17: Vendor releases interim fix. Updated "Description", "Solution Status" and "Solution" sections.
2005-10-19: Vendor provided download link to interim fix. Updated "Description", "Solution" and "Original Advisory" sections.
2005-10-31: Vendor releases Fix Pack 3 for WebSphere Application Server 6.0.2. Updated "Solution" and "Original Advisory" sections.
2007-07-17: Added IBM Rational ClearQuest in list of affected products based on new vendor advisory. Updated "Solution" section and added additional links.
Original Advisory: http://www-1.ibm.com/support/docview.wss?uid=swg1PK11929
http://www-1.ibm.com/support/docview.wss?uid=swg1PK13230
http://www-1.ibm.com/support/docview.wss?uid=swg24010709
http://www-1.ibm.com/support/docview.wss?uid=swg1PK13891
http://www-1.ibm.com/support/docview.wss?uid=swg1PK13980
http://www-1.ibm.com/support/docview.wss?uid=swg1PK42216
Other References: SA16688:
http://secunia.com/advisories/16688/
SA16559:
http://secunia.com/advisories/16559/
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
51 Related Secunia Security Advisories, displaying 10
|
|
|
1. IBM WebSphere Application Server Unspecified Vulnerability
|
|
2. IBM WebSphere Application Server Web Services Unspecified Vulnerability
|
|
3. IBM HTTP Server Multiple Cross-Site Scripting Vulnerabilities
|
|
4. IBM WebSphere Application Server Java Plugin Security Bypass
|
|
5. IBM WebSphere Application Server serveServletsByClassnameEnabled Information Disclosure
|
|
6. IBM Rational ClearQuest Cross-Site Scripting Vulnerabilities
|
|
7. IBM Rational ClearQuest Web User Enumeration Weakness
|
|
8. WebSphere Application Server Two Vulnerabilities
|
|
9. IBM WebSphere Application Server serveServletsByClassnameEnabled Information Disclosure
|
|
10. IBM WebSphere Application Server WebContainer "Expect" Header Cross-Site Scripting
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|