CVE-2009-1191
medium · 5mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request.
5
CVSS
12.4%
EPSS (exploit prob.)
96th
EPSS percentile
2009-04-23
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | 2.2.11 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 8.04 |
| canonical | ubuntu_linux | 8.10 |
| canonical | ubuntu_linux | 9.04 |
Check a specific version with /api/v1/cve/match.
References
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
- http://osvdb.org/53921
- http://secunia.com/advisories/34827
- http://secunia.com/advisories/35395
- http://secunia.com/advisories/35721
- http://security.gentoo.org/glsa/glsa-200907-04.xml
- http://support.apple.com/kb/HT3937
- http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=766938&r2=767089
- http://www.apache.org/dist/httpd/patches/apply_to_2.2.11/PR46949.diff
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:102
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
- http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
- http://www.securityfocus.com/bid/34663
- http://www.securitytracker.com/id?1022264
- http://www.ubuntu.com/usn/usn-787-1
- http://www.vupen.com/english/advisories/2009/1147
- http://www.vupen.com/english/advisories/2009/3184
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50059
- https://issues.apache.org/bugzilla/show_bug.cgi?id=46949
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-1191