PT-2010-3131 · Apache+2 · Apache Http Server+2

Published

2010-07-25

·

Updated

2024-06-15

·

CVE-2010-1452

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.2.x through 2.2.15
Description A flaw in the handling of requests by the mod cache and mod dav modules allows remote attackers to cause a denial of service, resulting in a process crash, via a request that lacks a path. This issue is mitigated as mod dav is only affected by requests that are most likely to be authenticated, and mod cache is only affected if the uncommon "CacheIgnoreURLSessionIdentifiers" directive is used.
Recommendations For Apache HTTP Server versions 2.2.x through 2.2.15, update to version 2.2.16 or later to resolve the issue. As a temporary workaround, consider disabling the mod cache and mod dav modules until a patch is available. Restrict access to the affected modules to minimize the risk of exploitation. Avoid using the "CacheIgnoreURLSessionIdentifiers" directive in the mod cache module until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-1452
HPSBUX02612
OPENSUSE-SU-2024:10268-1
RHSA-2010:0659
RHSA-2010_0659
RHSA-2011:0897

Affected Products

Apache Http Server
Hp-Ux
Red Hat