Short Name |
HTTP:APACHE:PHP-INVALID-HDR |
|---|---|
Severity |
Medium |
Recommended |
No |
Category |
HTTP |
Keywords |
apache php headers dos |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
di-5.3+ |
This signature detects attempts to exploit a known vulnerability against the Apache HTTP daemon. PHP versions 4.2.0 and 4.2.1 running on Apache 1.3.26 are vulnerable. Attackers can use invalid headers in an HTTP request to crash the Apache HTTP daemon; the daemon might require a manual restart.
PHP is a widely deployed scripting language, designed for web based development and CGI programming. PHP does not perform proper bounds checking on in functions related to Form-based File Uploads in HTML (RFC1867). Specifically, this problem occurs in the functions which are used to decode MIME encoded files. As a result, it may be possible to overrun the buffer used for the vulnerable functions to cause arbitrary attacker-supplied instructions to be executed. PHP is invoked through webservers remotely. It may be possible for remote attackers to execute this vulnerability to gain access to target systems. A vulnerable PHP interpreter module is available for Apache servers that is often enabled by default.