5

CVE-2008-2364

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheHTTP Server Version >= 2.0.35 < 2.0.64
ApacheHTTP Server Version >= 2.2.0 < 2.2.9
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version7.10
CanonicalUbuntu Linux Version8.04 SwEdition-
FedoraprojectFedora Version8
FedoraprojectFedora Version9
RedhatEnterprise Linux Eus Version4.7
RedhatEnterprise Linux Eus Version5.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.7% 0.927
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

http://marc.info/?l=bugtraq&m=125631037611762&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://www.securityfocus.com/bid/31681
Third Party Advisory
VDB Entry
http://marc.info/?l=bugtraq&m=123376588623823&w=2
Third Party Advisory
Mailing List
Issue Tracking
http://secunia.com/advisories/30621
Vendor Advisory
Not Applicable
http://www.securityfocus.com/bid/29653
Patch
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1020267
Third Party Advisory
Broken Link
VDB Entry