CVE-2008-2364
medium · 5The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
5
CVSS
12.7%
EPSS (exploit prob.)
96th
EPSS percentile
2008-06-13
Published
AV:N/AC:L/Au:N/C:N/I:N/A:P
Weaknesses
CWE-770
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | >= 2.0.35, < 2.0.64 |
| apache | http_server | >= 2.2.0, < 2.2.9 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 7.10 |
| canonical | ubuntu_linux | 8.04 |
| fedoraproject | fedora | 8 |
| fedoraproject | fedora | 9 |
| redhat | enterprise_linux_desktop | 3.0 |
| redhat | enterprise_linux_desktop | 4.0 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_eus | 4.7 |
| redhat | enterprise_linux_eus | 5.2 |
| redhat | enterprise_linux_server | 3.0 |
| redhat | enterprise_linux_server | 4.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_workstation | 3.0 |
| redhat | enterprise_linux_workstation | 4.0 |
| redhat | enterprise_linux_workstation | 5.0 |
Check a specific version with /api/v1/cve/match.
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
- http://marc.info/?l=bugtraq&m=123376588623823&w=2
- http://marc.info/?l=bugtraq&m=125631037611762&w=2
- http://rhn.redhat.com/errata/RHSA-2008-0967.html
- http://secunia.com/advisories/30621
- http://secunia.com/advisories/31026
- http://secunia.com/advisories/31404
- http://secunia.com/advisories/31416
- http://secunia.com/advisories/31651
- http://secunia.com/advisories/31904
- http://secunia.com/advisories/32222
- http://secunia.com/advisories/32685
- http://secunia.com/advisories/32838
- http://secunia.com/advisories/33156
- http://secunia.com/advisories/33797
- http://secunia.com/advisories/34219
- http://secunia.com/advisories/34259
- http://secunia.com/advisories/34418
- http://security.gentoo.org/glsa/glsa-200807-06.xml
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1
- http://support.apple.com/kb/HT3216
- http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&r2=666153&pathrev=666154
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-2364