PT-2004-1349 · Freebsd+5 · Freebsd+6
Published
2004-03-18
·
Updated
2024-02-15
·
CVE-2004-0174
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache versions 1.3.x through 1.3.29
Apache versions 1.4.x through 2.0.48
Description
A denial of service issue occurs when a short-lived connection on a rarely-accessed listening socket causes a child to hold the accept mutex and block out new connections until another connection arrives on that rarely-accessed listening socket. This issue affects certain platforms, including some versions of AIX, Solaris, and Tru64, but does not affect FreeBSD or Linux.
Recommendations
For Apache versions 1.3.x through 1.3.29, update to version 1.3.30 or later to resolve the issue.
For Apache versions 1.4.x through 2.0.48, update to version 2.0.49 or later to resolve the issue.
As a temporary workaround, consider restricting access to rarely-accessed listening sockets to minimize the risk of exploitation.
Fix
DoS
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aix
Apache
Apache Http Server
Freebsd
Linux
Solaris
Tru64