Oracle issues out-of-band Apache update

News

Oracle issues out-of-band Apache update

Hillary O'Rourke, Contributor

Oracle Corp. has issued an out-of-band security alert addressing a denial-of-service vulnerability in the open source Apache Web server that could affect some of its server components. The update, released Sept. 15, affects Oracle Fusion Middleware and Application Server products.

The vulnerability could be exploited remotely without authentication and could enable an attacker to crash a system over a network without account credentials.

To exploit the flaw, an attacker can ask for multiple overlapping parts of a large file in a single request. The vulnerability allows attackers to mount an Apache DDoS attack without having masses of computing firepower at their disposal, according to Sophos Security Consultant Paul Ducklin.

“This is only the fifth time Oracle has issued an alert outside its routine quarterly patch cycle since introducing its own version of Patch Tuesday at the start of 2005,” Ducklin wrote in Sophos’ Naked Security blog.

The vulnerability was discovered to be fairly easily exploitable by abusing a feature in Web servers that allows users to restart, pause and resume interrupted downloads or to permit large files to be overlapped as smaller files and stitched together later.

This

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

is the second official patch for the DDoS vulnerability, CVE-2011-3192. The Apache Software Foundation issued at critical update at the end of August when the company announced they had released version 2.2.20 of the Apache HTTP Server to fix the flaw. Oracle quickly produced that patch after identifying it in the wild a week before.

In its security advisory, Oracle warns, “Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Security Alert fixes as soon as possible.”


Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.