漏洞信息详情
Apache HTTP Server 资源管理错误漏洞
- CNNVD编号:CNNVD-200801-086
- 危害等级: 中危
- CVE编号:
CVE-2007-6422
- 漏洞类型:
资源管理错误
- 发布时间:
2007-05-16
- 威胁类型:
远程
- 更新时间:
2021-08-16
- 厂 商:
apache - 漏洞来源:
Luigi Auriemma※ al… -
漏洞简介
Apache HTTP Server是美国阿帕奇软件(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点。
Apache HTTP Server 2.2.0 through 2.2.6存在资源管理错误漏洞,该漏洞允许远程身份验证用户通过无效的变量导致拒绝服务。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Ubuntu Ubuntu Linux 7.10 powerpc
Ubuntu apache2-doc_2.2.4-3ubuntu0.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.2. 4-3ubuntu0.2_all.deb
Ubuntu apache2-mpm-event_2.2.4-3ubuntu0.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-even t_2.2.4-3ubuntu0.2_powerpc.deb
Ubuntu apache2-mpm-perchild_2.2.4-3ubuntu0.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perc hild_2.2.4-3ubuntu0.2_all.deb
Ubuntu apache2-mpm-prefork_2.2.4-3ubuntu0.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-pref ork_2.2.4-3ubuntu0.2_powerpc.deb
Ubuntu apache2-mpm-worker_2.2.4-3ubuntu0.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-work er_2.2.4-3ubuntu0.2_powerpc.deb
Ubuntu apache2-prefork-dev_2.2.4-3ubuntu0.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork- dev_2.2.4-3ubuntu0.2_powerpc.deb
Ubuntu apache2-src_2.2.4-3ubuntu0.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-src_2.2. 4-3ubuntu0.2_all.deb
Ubuntu apache2-threaded-dev_2.2.4-3ubuntu0.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded -dev_2.2.4-3ubuntu0.2_powerpc.deb
Ubuntu apache2-utils_2.2.4-3ubuntu0.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2. 2.4-3ubuntu0.2_powerpc.deb
Ubuntu apache2.2-common_2.2.4-3ubuntu0.2_powerpc.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2.2-common _2.2.4-3ubuntu0.2_powerpc.deb
Ubuntu apache2_2.2.4-3ubuntu0.2_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.4-3u buntu0.2_all.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu apache2-doc_2.2.8-1ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.2. 8-1ubuntu0.4_all.deb
Ubuntu apache2-mpm-event_2.2.8-1ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/a/apache2/apache2-mpm-event_2.2.8-1u buntu0.4_powerpc.deb
Ubuntu apache2-mpm-perchild_2.2.8-1ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perc hild_2.2.8-1ubuntu0.4_all.deb
Ubuntu apache2-mpm-prefork_2.2.8-1ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/a/apache2/apache2-mpm-prefork_2.2.8- 1ubuntu0.4_powerpc.deb
Ubuntu apache2-mpm-worker_2.2.8-1ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/a/apache2/apache2-mpm-worker_2.2.8-1 ubuntu0.4_powerpc.deb
Ubuntu apache2-prefork-dev_2.2.8-1ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/a/apache2/apache2-prefork-dev_2.2.8- 1ubuntu0.4_powerpc.deb
Ubuntu apache2-src_2.2.8-1ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-src_2.2. 8-1ubuntu0.4_all.deb
Ubuntu apache2-threaded-dev_2.2.8-1ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/a/apache2/apache2-threaded-dev_2.2.8 -1ubuntu0.4_powerpc.deb
Ubuntu apache2-utils_2.2.8-1ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/a/apache2/apache2-utils_2.2.8-1ubunt u0.4_powerpc.deb
Ubuntu apache2.2-common_2.2.8-1ubuntu0.4_powerpc.deb
http://ports.ubuntu.com/pool/main/a/apache2/apache2.2-common_2.2.8-1ub untu0.4_powerpc.deb
Ubuntu apache2_2.2.8-1ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.8-1u buntu0.4_all.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu apache2-doc_2.2.8-1ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.2. 8-1ubuntu0.4_all.deb
Ubuntu apache2-mpm-event_2.2.8-1ubuntu0.4_sparc.deb
http://ports.ubuntu.com/pool/main/a/apache2/apache2-mpm-event_2.2.8-1u buntu0.4_sparc.deb
Ubuntu apache2-mpm-perchild_2.2.8-1ubuntu0.4_all.deb
http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perc hild_2.2.8-1ubuntu0.4_all.deb
Ubuntu apache2-mpm-prefork_2.2.8-1ubuntu0.4_sparc.deb
http://ports.ubuntu.com/pool/main/a/apache2/apache2-mpm-prefork_2.2.8- 1ubuntu0.4_sparc.deb
Ubuntu apache2-mpm-worker_2.2.8-1ubuntu0.4_sparc.deb
参考网址
来源:httpd.apache.org%3E
链接:httpd.apache.org%3E
来源:MLIST
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html
来源:SECUNIA
链接:http://secunia.com/advisories/28977
来源:VUPEN
链接:http://www.vupen.com/english/advisories/2008/0048
来源:MLIST
来源:GENTOO
链接:http://security.gentoo.org/glsa/glsa-200803-19.xml
来源:FEDORA
链接:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.html
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8690
来源:httpd.apache.org
链接:httpd.apache.org/security/vulnerabilities_22.html
来源:MLIST
来源:MLIST
来源:SREASON
链接:http://securityreason.com/securityalert/3523
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10181
来源:SECUNIA
链接:http://secunia.com/advisories/28749
来源:MLIST
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/486169/100/0/threaded
来源:SECUNIA
链接:http://secunia.com/advisories/28526
来源:BID
链接:https://www.securityfocus.com/bid/27236
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/39476
来源:MLIST
来源:MLIST
来源:MLIST
来源:REDHAT
链接:http://www.redhat.com/support/errata/RHSA-2008-0009.html
来源:UBUNTU
链接:http://www.ubuntu.com/usn/usn-575-1
来源:MLIST
来源:REDHAT
链接:http://www.redhat.com/support/errata/RHSA-2008-0008.html
来源:MLIST
来源:MANDRIVA
链接:http://www.mandriva.com/security/advisories?name=MDVSA-2008:016
来源:SECUNIA
链接:http://secunia.com/advisories/29348
来源:MLIST
来源:MLIST
来源:SECUNIA
链接:http://secunia.com/advisories/29640
来源:FEDORA
链接:https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.html