PT-2009-5089 · Apache+2 · Apache Http Server+3
Published
2009-09-23
·
Updated
2024-06-15
·
CVE-2009-2699
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Portable Runtime (APR) library versions prior to 1.3.9
Apache HTTP Server versions prior to 2.2.14
Description
The issue is related to faulty error handling in the Solaris pollset feature of the Event Port backend in the APR library. This allows remote attackers to cause a denial of service, resulting in a daemon hang, via unspecified HTTP requests. The issue is specifically related to the prefork and event MPMs.
Recommendations
For Apache Portable Runtime (APR) library versions prior to 1.3.9, update to version 1.3.9 or later.
For Apache HTTP Server versions prior to 2.2.14, update to version 2.2.14 or later.
Fix
DoS
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Apache Portable Runtime
Solaris
Suse