← All CVEs

CVE-2009-1891

high · 7.1

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).

7.1
CVSS
17.1%
EPSS (exploit prob.)
97th
EPSS percentile
2009-07-10
Published

AV:N/AC:M/Au:N/C:N/I:N/A:C

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
apachehttp_server>= 2.0.35, < 2.0.64
apachehttp_server>= 2.2.0, < 2.2.12
debiandebian_linux4.0
debiandebian_linux5.0
debiandebian_linux6.0
fedoraprojectfedora11
canonicalubuntu_linux6.06
canonicalubuntu_linux8.04
canonicalubuntu_linux8.10
canonicalubuntu_linux9.04
redhatenterprise_linux_desktop5.0
redhatenterprise_linux_eus5.3
redhatenterprise_linux_server5.0
redhatenterprise_linux_server_aus5.3
redhatenterprise_linux_workstation5.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1891