5

CVE-2010-0408

The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version2.2
ApacheHTTP Server Version2.2.0
ApacheHTTP Server Version2.2.2
ApacheHTTP Server Version2.2.3
ApacheHTTP Server Version2.2.4
ApacheHTTP Server Version2.2.6
ApacheHTTP Server Version2.2.8
ApacheHTTP Server Version2.2.9
ApacheHTTP Server Version2.2.11
ApacheHTTP Server Version2.2.12
ApacheHTTP Server Version2.2.13
ApacheHTTP Server Version2.2.14
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 30.73% 0.966
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
http://marc.info/?l=bugtraq&m=127557640302499&w=2
Third Party Advisory
Mailing List
http://www.debian.org/security/2010/dsa-2035
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=569905
Third Party Advisory
Issue Tracking