Apache mod_proxy stream_reqbody_cl() Infinite Loop Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1022509
|
|
SecurityTracker URL: http://securitytracker.com/id?1022509
|
|
CVE Reference: CVE-2009-1890
(Links to External Site)
|
Date: Jul 3 2009
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Description: A vulnerability was reported in Apache mod_proxy. A remote user can cause denial of service conditions.
A remote user can send specially crafted Content-Length value to cause the stream_reqbody_cl() function in 'modules/proxy/mod_proxy_http.c' to enter an infinite loop.
|
Impact: A remote user can cause the target service to enter an infinite loop.
|
Solution: The vendor has issued a source code fix, available at:
http://svn.apache.org/viewvc?view=rev&revision=790587
|
Vendor URL: www.apache.org/ (Links to External Site)
|
Cause: State error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Fri, 3 Jul 2009 10:35:43 -0400
Subject: Apache mod_proxy
|
http://svn.apache.org/viewvc/httpd/httpd/trunk/CHANGES?r1=790587&r2=790586&pathrev=790587
CVE-2009-1890
|
|