CVE-2008-2364

Apache HTTP Server 2.0.35-2.0.63 - Denial of Service via Unlimited Interim Responses

Title source: llm
STIX 2.1

Description

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.

References (66)

Core 66
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34259
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34219
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31026
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=125631037611762&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31651
Broken Link vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31681
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32838
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/498567/100/0/threaded
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31904
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2008-0967.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32222
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00055.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00153.html
Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29653
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34418
Not Applicable, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30621
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32685
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42987
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31416
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020267
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-731-1
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/0320
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27008517
Third Party Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2008-0966.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33156
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33797
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/494858/100/0/threaded
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31404
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200807-06.xml
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2780
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=123376588623823&w=2
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:237
Permissions Required vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1798
Broken Link, Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html
Broken Link x_refsource_confirm
http://support.apple.com/kb/HT3216
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:195
Third Party Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK67579

Scores

EPSS 0.1271
EPSS Percentile 95.8%

Details

CWE
CWE-770
Status published
Products (17)
apache/http_server 2.0.35 - 2.0.64
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 7.10
canonical/ubuntu_linux 8.04
fedoraproject/fedora 8
fedoraproject/fedora 9
redhat/enterprise_linux_desktop 3.0
redhat/enterprise_linux_desktop 4.0
redhat/enterprise_linux_desktop 5.0
redhat/enterprise_linux_eus 4.7
... and 7 more
Published Jun 13, 2008
Tracked Since Feb 18, 2026