Lucene search

K
httpdApache Team FoundationHTTPD:6D37F924288E2D149DC3C52135232B6E
HistoryAug 21, 2009 - 12:00 a.m.

Apache Httpd < 2.2.17 : expat DoS

2009-08-2100:00:00
Apache Team Foundation
httpd.apache.org
25

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.027

Percentile

90.6%

A buffer over-read flaw was found in the bundled expat library. An attacker who is able to get Apache to parse an untrused XML document (for example through mod_dav) may be able to cause a crash. This crash would only be a denial of service if using the worker MPM.

Affected configurations

Vulners
Node
apacheapache_httpdMatch2.2.16
OR
apacheapache_httpdMatch2.2.15
OR
apacheapache_httpdMatch2.2.14
OR
apacheapache_httpdMatch2.2.13
OR
apacheapache_httpdMatch2.2.12
OR
apacheapache_httpdMatch2.2.11
OR
apacheapache_httpdMatch2.2.10
OR
apacheapache_httpdMatch2.2.9
OR
apacheapache_httpdMatch2.2.8
OR
apacheapache_httpdMatch2.2.6
OR
apacheapache_httpdMatch2.2.5
OR
apacheapache_httpdMatch2.2.4
OR
apacheapache_httpdMatch2.2.3
OR
apacheapache_httpdMatch2.2.2
OR
apacheapache_httpdMatch2.2.0
VendorProductVersionCPE
apacheapache_httpd2.2.16cpe:2.3:a:apache:apache_httpd:2.2.16:*:*:*:*:*:*:*
apacheapache_httpd2.2.15cpe:2.3:a:apache:apache_httpd:2.2.15:*:*:*:*:*:*:*
apacheapache_httpd2.2.14cpe:2.3:a:apache:apache_httpd:2.2.14:*:*:*:*:*:*:*
apacheapache_httpd2.2.13cpe:2.3:a:apache:apache_httpd:2.2.13:*:*:*:*:*:*:*
apacheapache_httpd2.2.12cpe:2.3:a:apache:apache_httpd:2.2.12:*:*:*:*:*:*:*
apacheapache_httpd2.2.11cpe:2.3:a:apache:apache_httpd:2.2.11:*:*:*:*:*:*:*
apacheapache_httpd2.2.10cpe:2.3:a:apache:apache_httpd:2.2.10:*:*:*:*:*:*:*
apacheapache_httpd2.2.9cpe:2.3:a:apache:apache_httpd:2.2.9:*:*:*:*:*:*:*
apacheapache_httpd2.2.8cpe:2.3:a:apache:apache_httpd:2.2.8:*:*:*:*:*:*:*
apacheapache_httpd2.2.6cpe:2.3:a:apache:apache_httpd:2.2.6:*:*:*:*:*:*:*
Rows per page:
1-10 of 151

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.027

Percentile

90.6%