PT-2003-1465 · Apache · Apache+1

Published

2003-07-09

·

Updated

2021-06-06

·

CVE-2003-0254

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: Apache versions prior to 2.0.47
Description: The issue occurs when the FTP proxy server fails to create an IPv6 socket, leading to an infinite loop and causing a denial of service due to CPU consumption. This happens when a client requests that the proxy ftp connect to a ftp server with an IPv6 address and the proxy is unable to create an IPv6 socket.
Recommendations: For Apache versions prior to 2.0.47, update to version 2.0.47 or later to resolve the issue. As a temporary workaround, consider restricting access to the FTP proxy server to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0254

Affected Products

Apache
Apache Http Server