Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Apache HTTP Server mod_cache Module Denial of Service Vulnerability

Subscribe

Check Point Reference: CPAI-2008-013
Date Published:
Severity:
Source: Secunia Advisory: SA25830
Industry Reference(s): CVE-2007-1863
Protection Provided by: VPN-1
  • NGX R65
  • NGX R62
  • NGX R61
  • NGX R60
  • NG with Application Intelligence R55
VSX
  • NGX
InterSpect
  • NGX
Connectra
  • NGX R62
  • NGX R61
Who is Vulnerable?
Apache Software Foundation HTTP Server 2.2.x
Apache Software Foundation HTTP Server 2.0.x
Vulnerability Description
A denial of service vulnerability was reported in the mod_cache module of the Apache HTTP Server. Apache is a popular web server available for a wide variety of operating systems. The mod_cache module is one of the official plug-in modules for Apache. An attacker may exploit this vulnerability to create a denial of service condition on an affected system.
Vulnerability Details
The vulnerability is due to an error in the mod_cache module that fails to properly handle specially crafted Cache-Control headers. A remote attacker can exploit this issue by specially crafting a malicious HTTP request and sending it an affected server. Successful exploitation may create a denial of service condition on the target host.

Protection Overview
By enabling this protection, SmartDefense will detect and block any attempt to exploit this vulnerability.

In order for the protection to be activated, update your VPN-1/InterSpect/Connectra product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

VPN-1 NGX R65 & R62

How Can I Protect My Network?
1. In the SmartDefense tab, click Application Intelligence > Web Servers > Apache > Block Apache mod_cache DOS Vulnerability.
2. In the configuration pane, under Settings > Mode, check Active.
3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Apache Server Protection Violation
Attack Information: HTTP server mod_cache module DoS attempt detected

VPN-1 NGX R61 & R60

How Can I Protect My Network?
1. In the SmartDefense tree, click Application Intelligence > Web Servers > Apache.
2. Select the following:

Block Apache mod_cache DoS Vulnerability

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Apache Server Protection Violation
Attack Information: HTTP server mod_cache module DoS attempt detected

VPN-1 NG with Application Intelligence R55

How Can I Protect My Network?
1. In the SmartDefense tree, click Application Intelligence > Web Servers > Apache.
2. Select the following protection:

Block Apache mod_cache DoS Vulnerability

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
Rule #99908 will appear on the SmartView Tracker.

VPN-1 VSX NGX

How Can I Protect My Network?
1. In the SmartDefense tree, click Application Intelligence > Web Servers > Apache.
2. Select the following protection:

Block Apache mod_cache DoS Vulnerability

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
Rule #99908 will appear on the SmartView Tracker.

InterSpect NGX

How Can I Protect My Network?
1. In the left pane, select Profiles > Default Protection and select the SmartDefense page of the profile.
2. In the SmartDefense tree, click Application Intelligence > Web Servers > Apache.
3. Select the following protection:

Block Apache mod_cache DoS Vulnerability

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Apache Server Protection Violation
Attack Information: HTTP server mod_cache module DoS attempt detected

Connectra NGX R62 & R61

How Can I Protect My Network?
1. In the left-hand menu, click Security > SmartDefense > Application Intelligence.
2. In the Dynamic Attacks pane, select the following:

Block Apache mod_cache DoS Vulnerability

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Attack Name: Apache Server Protection Violation
Attack Information: HTTP server mod_cache module DoS attempt detected