← All CVEs

CVE-2008-2364

medium · 5

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.

5
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2008-06-13
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-770

Affected products

VendorProductAffected versions
apachehttp_server>= 2.0.35, < 2.0.64
apachehttp_server>= 2.2.0, < 2.2.9
canonicalubuntu_linux6.06
canonicalubuntu_linux7.10
canonicalubuntu_linux8.04
fedoraprojectfedora8
fedoraprojectfedora9
redhatenterprise_linux_desktop3.0
redhatenterprise_linux_desktop4.0
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_eus4.7
redhatenterprise_linux_eus5.2
redhatenterprise_linux_server3.0
redhatenterprise_linux_server4.0
redhatenterprise_linux_server5.0
redhatenterprise_linux_workstation3.0
redhatenterprise_linux_workstation4.0
redhatenterprise_linux_workstation5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-2364