PT-2010-3131 · Apache+2 · Apache Http Server+2

Publicado

2010-07-25

·

Atualizado

2024-06-15

·

CVE-2010-1452

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.x through 2.2.15
Description A flaw in the handling of requests by the mod cache and mod dav modules allows remote attackers to cause a denial of service, resulting in a process crash, via a request that lacks a path. This issue is mitigated as mod dav is only affected by requests that are most likely to be authenticated, and mod cache is only affected if the uncommon "CacheIgnoreURLSessionIdentifiers" directive is used.
Recommendations For Apache HTTP Server versions 2.2.x through 2.2.15, update to version 2.2.16 or later to resolve the issue. As a temporary workaround, consider disabling the mod cache and mod dav modules until a patch is available. Restrict access to the affected modules to minimize the risk of exploitation. Avoid using the "CacheIgnoreURLSessionIdentifiers" directive in the mod cache module until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-1452
HPSBUX02612
OPENSUSE-SU-2024:10268-1
RHSA-2010:0659
RHSA-2010_0659
RHSA-2011:0897

Produtos afetados

Apache Http Server
Hp-Ux
Red Hat