5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
0.425 Medium
EPSS
Percentile
97.3%
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | apache2 | < 2.2.16-3 | apache2_2.2.16-3_all.deb |
Debian | 11 | all | apache2 | < 2.2.16-3 | apache2_2.2.16-3_all.deb |
Debian | 999 | all | apache2 | < 2.2.16-3 | apache2_2.2.16-3_all.deb |
Debian | 13 | all | apache2 | < 2.2.16-3 | apache2_2.2.16-3_all.deb |
Debian | 12 | all | apr-util | < 1.3.9+dfsg-4 | apr-util_1.3.9+dfsg-4_all.deb |
Debian | 11 | all | apr-util | < 1.3.9+dfsg-4 | apr-util_1.3.9+dfsg-4_all.deb |
Debian | 999 | all | apr-util | < 1.3.9+dfsg-4 | apr-util_1.3.9+dfsg-4_all.deb |
Debian | 13 | all | apr-util | < 1.3.9+dfsg-4 | apr-util_1.3.9+dfsg-4_all.deb |