Bug 62740 (CVE-2004-0940) - VUL-0: CVE-2004-0940: apache 1.3 mod_include local overflow
Summary: VUL-0: CVE-2004-0940: apache 1.3 mod_include local overflow
Status: RESOLVED FIXED
Alias: CVE-2004-0940
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All Linux
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Peter Poeml
QA Contact: Security Team bot
URL:
Whiteboard: CVE-2004-0940: CVSS v2 Base Score: 6....
Keywords:
Depends on:
Blocks:
 
Reported: 2004-10-28 19:49 UTC by Marcus Meissner
Modified: 2021-10-04 10:21 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
exploit.txt (3.89 KB, text/plain)
2004-10-28 19:50 UTC, Marcus Meissner
Details
apache.patch.box (991 bytes, text/plain)
2004-11-11 02:58 UTC, Peter Poeml
Details
apache.patch.maintained (898 bytes, text/plain)
2004-11-11 02:58 UTC, Peter Poeml
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2004-10-28 19:49:31 UTC
From a customer (ticket 20041027430001574): 
 
> bin gestern per Zufall auf den Link gestossen: 
> <a href="http://www.xakep.ru/post/24453/exploit.txt">exploit</a> 
> Ist da was wahres dran, oder ist der Apache 1.3.x schon immun dagegen?
Comment 1 Marcus Meissner 2004-10-28 19:49:31 UTC
<!-- SBZ_reproduce  -->
n/a
Comment 2 Marcus Meissner 2004-10-28 19:50:11 UTC
Created attachment 25558 [details]
exploit.txt

above url content
Comment 3 Marcus Meissner 2004-10-28 19:51:43 UTC
This seems to be local only.  
 
I would like to see it fixed at one point in time for the released products. 
Comment 4 Joerg Reuter 2004-10-28 22:55:26 UTC
Yes, it is a local vulnerability, but it can bite any web hoster who has enabled
server side includes (SSI) and allows his users to upload their web pages
without prior validation (which is the norm.). Taking into account that this bug
is semi-public (I cannot find anything about it in my local archives of
full-disclosure and bugtraq) I'd say that it is likely more serious than it
might seem on the first look.
Comment 5 Marcus Meissner 2004-10-29 17:12:58 UTC
apache now announced an advisory and new release. 
 
http://www.apache.org/dist/httpd/Announcement.html 
 
 
CAN-2004-0940 (cve.mitre.org) 
 Fix potential buffer overflow with escaped characters in SSI tag string. 
  
CAN-2004-0492 (cve.mitre.org) 
 Reject responses from a remote server if sent an invalid (negative) 
Content-Length. 
 
Comment 6 Peter Poeml 2004-11-02 22:28:37 UTC
Do we do updates for this?
We can fix the SSLCipherSuite problem (bug 62117) at the same time.
Comment 7 Ludwig Nussel 2004-11-05 00:10:14 UTC
Considering Joergs argument about web hosters I'd say do the update. 
Comment 8 Peter Poeml 2004-11-10 23:19:28 UTC
Packages submitted:

/work/SRC/old-versions/8.1/UL/all/apache -> /work/src/done/8.1
/work/SRC/old-versions/8.2/all/apache -> /work/src/done/8.2
/work/SRC/old-versions/9.0/all/apache -> /work/src/done/9.0
/work/SRC/old-versions/9.1/SLES/all/apache -> /work/src/done/9.1

-------------------------------------------------------------------
Wed Nov 10 12:16:56 CET 2004 - poeml@suse.de

- security fix from 1.3.33:
  [CAN-2004-0940 (cve.mitre.org)]: mod_include: Fix potential
  buffer overflow with escaped characters in SSI tag string.
  [#47740]
- security fix from mod_ssl 2.8.20:
  [CAN-2004-0885 (cve.mitre.org)]: fix SSLCipherSuite bypass in
  mod_ssl [#47117]

-------------------------------------------------------------------

I will create the needed patchinfos.
Comment 9 Peter Poeml 2004-11-11 02:58:31 UTC
Created attachment 25984 [details]
apache.patch.box
Comment 10 Peter Poeml 2004-11-11 02:58:52 UTC
Created attachment 25985 [details]
apache.patch.maintained
Comment 11 Peter Poeml 2004-11-11 18:14:39 UTC
Packages checked in, patchinfo files submitted. 
I am assigning to security-team for further processing.
Comment 12 Thomas Biege 2004-11-19 23:03:45 UTC
approved 
Comment 13 Thomas Biege 2004-11-19 23:07:48 UTC
<!-- SBZ_reopen -->Reopened by thomas@suse.de at Fri Nov 19 16:07:48 2004, took initial reporter meissner@suse.de to cc
Comment 14 Thomas Biege 2004-11-19 23:07:48 UTC
oops ome package is still missing. :( 
 
http://w2d.suse.de/abuildstat/patchinfo/pending/e2d9838c404c87687b26f66baa345567 
Comment 15 Marcus Meissner 2004-11-24 04:23:39 UTC
approved now. 
Comment 16 Marcus Meissner 2004-11-25 01:10:55 UTC
<!-- SBZ_reopen -->Reopened by meissner@suse.de at Wed Nov 24 18:10:55 2004, took initial reporter thomas@suse.de to cc
Comment 17 Marcus Meissner 2004-11-25 01:10:55 UTC
Peter, is apache2 affected by this problem too? 
 
 
Comment 18 Peter Poeml 2004-11-25 22:10:20 UTC
I don't think so (the parser in mod_include is completely rewritten)
Comment 19 Thomas Biege 2009-10-13 19:56:09 UTC
CVE-2004-0940: CVSS v2 Base Score: 6.9 (AV:L/AC:M/Au:N/C:C/I:C/A:C)