Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:APACHE:MOD-NTLM-BOF1

Severity

Major

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Apache mod_ntlm Authorization Buffer Overflow 1

Release Date

2004/03/24

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Apache mod_ntlm Authorization Buffer Overflow 1


This signature detects attempts to exploit a known vulnerablility against Apache Web server. An Apache Web server uses mod_ntlm (an Apache 1.x and 2.x module) to authenticate users against a Microsoft Windows Domain Controller. Attackers can send long or malformed strings to mod_ntlm using the Authorization HTTP header, overflow the buffer, then execute arbitrary code on the Web server.

Extended Description

The mod_ntlm Apache module has been reported prone to a heap overflow vulnerability. The vulnerability occurs due to a lack of sufficient bounds checking performed on user-supplied data, stored in heap memory. By supplying excessive data an attacker may trigger a buffer overflow and corrupt crucial memory management structures. This may result in the execution of arbitrary code in the context of the Apache server. This vulnerability is reported to affect mod_ntlm <= v0.4 for Apache 1.3 and mod_ntlmv2 version 0.1 for Apache 2.0.

Affected Products

  • Mod_ntlm mod_ntlm 0.1.0
  • Mod_ntlm mod_ntlm 0.2.0
  • Mod_ntlm mod_ntlm 0.3.0
  • Mod_ntlm mod_ntlm 0.4.0
  • Mod_ntlm mod_ntlm2 0.1.0
  • Working_resources_inc. badblue_enterprise_edition 1.5.0
  • Working_resources_inc. badblue_enterprise_edition 1.5.6 Beta
  • Working_resources_inc. badblue_enterprise_edition 1.6.0 Beta
  • Working_resources_inc. badblue_enterprise_edition 1.7.0
  • Working_resources_inc. badblue_enterprise_edition 1.7.2
  • Working_resources_inc. badblue_enterprise_edition 1.7.3
  • Working_resources_inc. badblue_enterprise_edition 1.7.4
  • Working_resources_inc. badblue_enterprise_edition 2.15.0
  • Working_resources_inc. badblue_personal_edition 1.5.6 Beta
  • Working_resources_inc. badblue_personal_edition 1.6.0 Beta
  • Working_resources_inc. badblue_personal_edition 1.7.0
  • Working_resources_inc. badblue_personal_edition 1.7.2
  • Working_resources_inc. badblue_personal_edition 1.7.3
  • Working_resources_inc. badblue_personal_edition 1.7.4
  • Working_resources_inc. badblue_personal_edition 2.15.0

References

  • BugTraq: 7388
  • URL: http://www.securityfocus.com/archive/1/319239
  • URL: http://www.sourceforge.net/projects/modntlm
  • URL: http://sourceforge.net/tracker/index.php?func=detail&aid=723468&group_id=4906&atid=104906

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out