← All CVEs

CVE-2009-1890

high · 7.1

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.

7.1
CVSS
16.2%
EPSS (exploit prob.)
97th
EPSS percentile
2009-07-05
Published

AV:N/AC:M/Au:N/C:N/I:N/A:C

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
apachehttp_server>= 2.2.0, < 2.2.12
fedoraprojectfedora11
debiandebian_linux4.0
debiandebian_linux5.0
debiandebian_linux6.0
canonicalubuntu_linux6.06
canonicalubuntu_linux8.04
canonicalubuntu_linux8.10
canonicalubuntu_linux9.04
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_eus5.3
redhatenterprise_linux_server5.0
redhatenterprise_linux_server_aus5.3
redhatenterprise_linux_workstation5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1890