PT-2009-5089 · Apache+2 · Apache Http Server+3

Published

2009-09-23

·

Updated

2024-06-15

·

CVE-2009-2699

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Portable Runtime (APR) library versions prior to 1.3.9 Apache HTTP Server versions prior to 2.2.14
Description The issue is related to faulty error handling in the Solaris pollset feature of the Event Port backend in the APR library. This allows remote attackers to cause a denial of service, resulting in a daemon hang, via unspecified HTTP requests. The issue is specifically related to the prefork and event MPMs.
Recommendations For Apache Portable Runtime (APR) library versions prior to 1.3.9, update to version 1.3.9 or later. For Apache HTTP Server versions prior to 2.2.14, update to version 2.2.14 or later.

Fix

DoS

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2699
OPENSUSE-SU-2024:10268-1
SUSE-SU-2017:2907-1

Affected Products

Apache Http Server
Apache Portable Runtime
Solaris
Suse