PT-2004-1858 · Apache · Apr-Util+2
Published
2004-09-15
·
Updated
2022-09-23
·
CVE-2004-0786
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache versions prior to 2.0.51
Description
The issue is related to the IPv6 URI parsing routines in the apr-util library, which can be exploited by remote attackers to cause a denial of service, specifically a child process crash, by sending a request with a carefully crafted URI. In some cases, on certain BSD systems, this flaw may potentially lead to remote code execution.
Recommendations
For Apache versions prior to 2.0.51, update to version 2.0.51 or later to resolve the issue. As a temporary workaround, consider restricting access to the IPv6 URI parsing routines in the apr-util library until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Apache Http Server
Apr-Util