Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Apache Warning Fuels Security Feud

    Written by

    Dennis Fisher
    Published June 18, 2002
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The long-running dispute over when to release vulnerability information is escalating into a bitter turf war among several security companies, all of which claim to have their customers best interests at heart.

      The flap began Monday when news of a serious vulnerability in the popular Apache open-source Web server software hit security mailing lists. Security vendor Internet Security Systems Inc. released an advisory early Monday warning of the flaw. The ISS advisory also included a piece of code that the companys X-Force research team said would remedy the problem. There was no formal patch available for the flaw.

      The Apache Software Foundation, which maintains the Apache software, then released its own advisory, which not only criticized ISS for releasing its advisory before a patch was ready but also claimed that ISS patch didnt fix the vulnerability.

      The CERT Coordination Center, which acts as a kind of clearinghouse for vulnerability data and often coordinates its efforts with security researchers and vendors, published a bulletin late Monday as well.

      Several security researchers apparently found the Apache flaw virtually simultaneously, and thats where the problem arose. While ISS was preparing its bulletin, Next Generation Security Software Ltd., which had also discovered the problem, contacted CERT and the Apache Foundation, alerting them to the problem. The Apache developers said they wanted to coordinate the release of the bulletin with CERT, to which NGSS agreed, according to a note posted to the Bugtraq mailing list by David Litchfield, a well-known security researcher and co-founder of NGSS.

      “Of course, with a premature release from ISS many are now left vulnerable without a patch,” Litchfield wrote.

      Marc Maiffret, chief hacking officer of eEye Digital Security Inc., of Aliso Viejo, Calif., also joined the fray, saying that the early release of the vulnerability data will inevitably lead to active exploitation of the flaw by crackers.

      “Since there has actually been many chunked encoding vulnerabilities released lately, and exploits (for win32), it only makes sense that it will take no time for someone to develop an exploit for this Apache Win32 chunked overflow, and then start using that to break into systems,” he wrote in a reply to Litchfields message.

      The Apache flaw lies in the way that the server handles data transmissions of unknown size. Typically, these transmissions are broken into “chunks” for easier handling. But Apaches HTTP server misinterprets the size of the chunks, which leads to an overrun of the heap memory, according to an advisory published Monday by Internet Security Systems Inc.s X-Force research team.

      The vulnerability can be exploited remotely by way of a carefully crafted invalid request to the server, and the flawed functionality is enabled by default. Exploiting the flaw could either lead to a denial of service on the machine or the execution of malicious code.

      An attacker would only be able to execute code on 64-bit Unix systems and Windows machines, according to Apache. Exploiting the vulnerability on 32-bit Unix machines would crash the Apache HTTP server.

      The Apache Software Foundations Apache Server Project, which maintains the open-source HTTP server, also issued a bulletin warning that all versions of Apache 1.3 are vulnerable, as are copies of version 2 up to 2.0.39.

      Related stories:

      • Review: Covalent Gets Apache Enterprise Ready
      • Review: Apache 2.0 Beats IIS at Its Own Game
      • IBM Apache Avoids Most Security Woes
      • Flaw Puts SQL Servers at Risk
      • More Security Coverage
      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×