CVE-2008-2364
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 12.71% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-770
- Affected
- apache/http server · canonical/ubuntu linux · fedoraproject/fedora · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432Broken Link
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlBroken Link, Mailing List
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=123376588623823&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=125631037611762&w=2Issue Tracking, Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2008-0967.htmlThird Party Advisory
- http://secunia.com/advisories/30621Not Applicable, Vendor Advisory
- http://secunia.com/advisories/31026Not Applicable
- http://secunia.com/advisories/31404Not Applicable
- http://secunia.com/advisories/31416Not Applicable
- http://secunia.com/advisories/31651Not Applicable
- http://secunia.com/advisories/31904Not Applicable
- http://secunia.com/advisories/32222Not Applicable
- http://secunia.com/advisories/32685Not Applicable
- http://secunia.com/advisories/32838Not Applicable
- http://secunia.com/advisories/33156Not Applicable
- http://secunia.com/advisories/33797Not Applicable
- http://secunia.com/advisories/34219Not Applicable
- http://secunia.com/advisories/34259Not Applicable
- http://secunia.com/advisories/34418Not Applicable
- http://security.gentoo.org/glsa/glsa-200807-06.xmlThird Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1Broken Link
- http://support.apple.com/kb/HT3216Broken Link
- http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&r2=666153&pathrev=666154Patch, Vendor Advisory
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328Broken Link
- http://www-01.ibm.com/support/docview.wss?uid=swg27008517Third Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK67579Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:195Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:237Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.