CVE-2004-0174
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 11.55% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-667
- Affected
- apache/http server
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=107973894328806&w=2Mailing List, Patch
- http://marc.info/?l=bugtraq&m=108066914830552&w=2Mailing List, Patch
- http://marc.info/?l=bugtraq&m=108369640424244&w=2Mailing List, Patch
- http://marc.info/?l=bugtraq&m=108437852004207&w=2Mailing List
- http://marc.info/?l=bugtraq&m=108731648532365&w=2Mailing List, Patch
- http://secunia.com/advisories/11170Broken Link
- http://security.gentoo.org/glsa/glsa-200405-22.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101555-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-57628-1Broken Link
- http://www.apache.org/dist/httpd/CHANGES_1.3Broken Link
- http://www.kb.cert.org/vuls/id/132110Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:046Patch, Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2004-405.htmlBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/9921Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/alerts/2004/Mar/1009495.htmlBroken Link, Third Party Advisory, VDB Entry
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.529643Mailing List, Patch
- http://www.trustix.org/errata/2004/0027Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15540Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/raa117ef183f0da9b3f46efbeaa66f7622bd68868a450cae4fd8ed594%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
- https://lists.apache.org/thread.html/rd65d8ba68ba17e7deedafbf5bb4899f2ae4dad781d21b931c2941ac3%40%3Ccvs.httpd.apache.org%3EMailing List, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.