First published: Fri Jul 28 2006(Updated: )
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Http Server | >=2.2.0<2.2.3 | |
Apache Http Server | >=1.3.28<1.3.37 | |
Apache Http Server | >=2.0.46<2.0.59 | |
Ubuntu | =5.04 | |
Ubuntu | =5.10 | |
Ubuntu | =6.06 | |
Debian Linux | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3747 is considered to have a medium severity due to its potential to cause denial of service and possibly allow arbitrary code execution.
To fix CVE-2006-3747, upgrade your Apache HTTP Server to version 2.0.59 or later, or 2.2.0 or later.
CVE-2006-3747 affects Apache HTTP Server versions 1.3.28 to 1.3.37, 2.0.46 to 2.0.59, and certain versions of Ubuntu and Debian Linux.
Exploiting CVE-2006-3747 can lead to a denial of service attack resulting in application crashes or potentially executing arbitrary code.
While upgrading is the best solution for CVE-2006-3747, disabling the RewriteEngine may serve as a temporary workaround.