Feeds

Apache squashes 'devastating' bug under attack

Byte range vuln exposed servers to crippling DoS exploit

Top 5 reasons to deploy VMware with Tegile

Maintainers of the open-source Apache webserver have fixed a severe weakness that attackers are exploiting to crash websites.

Flaws in Apache's HTTP daemon made it easy to crash servers using publicly available software released last week. The bugs in the way the HTTPD processed multiple web requests that involved overlapping byte ranges allowed attackers to overwhelm servers by sending them a modest amount of traffic.

An advisory on Apache's website said the bug, formally known as CVE-2011-3192 has been fixed in version 2.2.20.

“We consider this release to be the best version of Apache available, and encourage users of all prior versions to upgrade,” the advisory stated. "Active use" of the attack tool has been observed.

One of the bugs fixed in the update was specific to Apache, while a second flaw has been known since 2007, and possibly involves all webservers, an Apache bulletin said. The Internet Engineering Task Force is considering changing the underlying protocol responsible for the problem, Apache said.

Versions 1.3.x and 2.0.x through 2.0.64 contain the denial-of-service vulnerabilities. They can be triggered by a single web request that contains overlapping byte ranges for a specific page.

“The problem is that currently such requests internally explode into 100's of large fetches, all of which are kept in memory in an inefficient way,” Apache's advisory explained. “This is being addressed in two ways. By making things more efficient. And by weeding out or simplifying requests deemed too unwieldy.” ®

Internet Security Threat Report 2014

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Home Depot ignored staff warnings of security fail laundry list
'Just use cash', former security staffer warns friends
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
BitTorrent's peer-to-peer chat app Bleep goes live as public alpha
A good day for privacy as invisble.im also reveals its approach to untraceable chats
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.