PT-2010-3131 · Apache+2 · Apache Http Server+2
Published
2010-07-25
·
Updated
2024-06-15
·
CVE-2010-1452
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.2.x through 2.2.15
Description
A flaw in the handling of requests by the mod cache and mod dav modules allows remote attackers to cause a denial of service, resulting in a process crash, via a request that lacks a path. This issue is mitigated as mod dav is only affected by requests that are most likely to be authenticated, and mod cache is only affected if the uncommon "CacheIgnoreURLSessionIdentifiers" directive is used.
Recommendations
For Apache HTTP Server versions 2.2.x through 2.2.15, update to version 2.2.16 or later to resolve the issue. As a temporary workaround, consider disabling the mod cache and mod dav modules until a patch is available. Restrict access to the affected modules to minimize the risk of exploitation. Avoid using the "CacheIgnoreURLSessionIdentifiers" directive in the mod cache module until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Http Server
Hp-Ux
Red Hat