PT-2004-1858 · Apache · Apr-Util+2

Published

2004-09-15

·

Updated

2022-09-23

·

CVE-2004-0786

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache versions prior to 2.0.51
Description The issue is related to the IPv6 URI parsing routines in the apr-util library, which can be exploited by remote attackers to cause a denial of service, specifically a child process crash, by sending a request with a carefully crafted URI. In some cases, on certain BSD systems, this flaw may potentially lead to remote code execution.
Recommendations For Apache versions prior to 2.0.51, update to version 2.0.51 or later to resolve the issue. As a temporary workaround, consider restricting access to the IPv6 URI parsing routines in the apr-util library until a patch is available.

Fix

Related Identifiers

CVE-2004-0786
RHSA-2004:463

Affected Products

Apache
Apache Http Server
Apr-Util