PT-2009-5089 · Apache+2 · Apache Http Server+3

Publicado

2009-09-23

·

Atualizado

2024-06-15

·

CVE-2009-2699

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Portable Runtime (APR) library versions prior to 1.3.9 Apache HTTP Server versions prior to 2.2.14
Description The issue is related to faulty error handling in the Solaris pollset feature of the Event Port backend in the APR library. This allows remote attackers to cause a denial of service, resulting in a daemon hang, via unspecified HTTP requests. The issue is specifically related to the prefork and event MPMs.
Recommendations For Apache Portable Runtime (APR) library versions prior to 1.3.9, update to version 1.3.9 or later. For Apache HTTP Server versions prior to 2.2.14, update to version 2.2.14 or later.

Correção

DoS

Improper Locking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2699
OPENSUSE-SU-2024:10268-1
SUSE-SU-2017:2907-1

Produtos afetados

Apache Http Server
Apache Portable Runtime
Solaris
Suse