CVE-2004-0748

Apache 2.0.50 - DoS

Title source: llm
STIX 2.1

Description

mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.

References (20)

Core 20
Core References
Broken Link vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2004_30_apache2.html
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=130750
Broken Link vendor-advisory x_refsource_trustix
http://www.trustix.org/errata/2004/0047/
Broken Link vendor-advisory x_refsource_mandrake
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-349.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17200

Scores

EPSS 0.1876
EPSS Percentile 95.3%

Details

CWE
CWE-835
Status published
Products (1)
apache/http_server 2.0.35 - 2.0.51
Published Oct 20, 2004
Tracked Since Feb 18, 2026