PT-2004-1349 · Freebsd+5 · Freebsd+6

Published

2004-03-18

·

Updated

2024-02-15

·

CVE-2004-0174

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache versions 1.3.x through 1.3.29 Apache versions 1.4.x through 2.0.48
Description A denial of service issue occurs when a short-lived connection on a rarely-accessed listening socket causes a child to hold the accept mutex and block out new connections until another connection arrives on that rarely-accessed listening socket. This issue affects certain platforms, including some versions of AIX, Solaris, and Tru64, but does not affect FreeBSD or Linux.
Recommendations For Apache versions 1.3.x through 1.3.29, update to version 1.3.30 or later to resolve the issue. For Apache versions 1.4.x through 2.0.48, update to version 2.0.49 or later to resolve the issue. As a temporary workaround, consider restricting access to rarely-accessed listening sockets to minimize the risk of exploitation.

Fix

DoS

Improper Locking

Weakness Enumeration

Related Identifiers

CVE-2004-0174

Affected Products

Aix
Apache
Apache Http Server
Freebsd
Linux
Solaris
Tru64