CVE-2004-0809

Apache HTTP Server 2.0.35-2.0.50 - Denial of Service via mod_dav LOCK Request Sequence

Title source: llm
STIX 2.1

Description

The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.

References (20)

Core 20
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-463.html
Broken Link, Exploit, Patch, Vendor Advisory vendor-advisory x_refsource_trustix
http://www.trustix.org/errata/2004/0047/
Broken Link vendor-advisory x_refsource_mandrake
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2004/dsa-558
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200409-21.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17366

Scores

EPSS 0.1402
EPSS Percentile 94.4%

Details

Status published
Products (26)
apache/http_server 2.0.35 - 2.0.51
debian/debian_linux 3.0
gentoo/linux 1.4
hp/hp-ux 11.00
hp/hp-ux 11.11
hp/hp-ux 11.22
hp/hp-ux 11.23
hp/secure_web_server_for_tru64 4.0_f
hp/secure_web_server_for_tru64 4.0_g
hp/secure_web_server_for_tru64 5.0_a
... and 16 more
Published Sep 16, 2004
Tracked Since Feb 18, 2026