PT-2004-1874 · Apache · Apache+1

Published

2004-09-12

·

Updated

2022-09-23

·

CVE-2004-0809

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache versions 2.0.50 and earlier
Description The issue is related to the mod dav module, which allows remote attackers to cause a denial of service by crashing a child process. This can be achieved by sending a specific sequence of LOCK requests to a location with WebDAV authoring access. The issue does not allow execution of arbitrary code and only results in a denial of service when a threaded process model is in use.
Recommendations For Apache versions 2.0.50 and earlier, consider disabling the mod dav module as a temporary workaround to prevent the denial of service. Restrict access to locations with WebDAV authoring access to minimize the risk of exploitation. Avoid using the LOCK method in affected locations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2004-0809
DSA-558-1
RHSA-2004:463

Affected Products

Apache
Apache Http Server