PT-2004-1874 · Apache · Apache+1
Published
2004-09-12
·
Updated
2022-09-23
·
CVE-2004-0809
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache versions 2.0.50 and earlier
Description
The issue is related to the mod dav module, which allows remote attackers to cause a denial of service by crashing a child process. This can be achieved by sending a specific sequence of LOCK requests to a location with WebDAV authoring access. The issue does not allow execution of arbitrary code and only results in a denial of service when a threaded process model is in use.
Recommendations
For Apache versions 2.0.50 and earlier, consider disabling the mod dav module as a temporary workaround to prevent the denial of service. Restrict access to locations with WebDAV authoring access to minimize the risk of exploitation. Avoid using the LOCK method in affected locations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Apache Http Server