CERTA-2005-AVI-427
Vulnerability from certfr_avis
Une vulnérabilité dans Apache 2.0 permet à un utilisateur distant de provoquer un déni de service.
Description
Une erreur dans le composant multi-tâche worker MPM de Apache 2.0 permet à un utilisateur distant mal-intentionné de provoquer une consommation excessive de la mémoire par le biais d'une requête HTTP malicieusement construite, occasionnant ainsi un déni de service.
Solution
La version 2.0.55 de Apache corrige le problème :
http://httpd.apache.org
Apache versions 2.0.54 et antérieures.
Impacted products
| Vendor | Product | Description |
|---|
References
| Title | Publication Time | Tags | |
|---|---|---|---|
|
|
|||
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [],
"affected_systems_content": "\u003cp\u003eApache versions 2.0.54 et ant\u00e9rieures.\u003c/p\u003e",
"content": "## Description\n\nUne erreur dans le composant multi-t\u00e2che worker MPM de Apache 2.0 permet\n\u00e0 un utilisateur distant mal-intentionn\u00e9 de provoquer une consommation\nexcessive de la m\u00e9moire par le biais d\u0027une requ\u00eate HTTP malicieusement\nconstruite, occasionnant ainsi un d\u00e9ni de service.\n\n## Solution\n\nLa version 2.0.55 de Apache corrige le probl\u00e8me :\n\n http://httpd.apache.org\n",
"cves": [],
"initial_release_date": "2005-11-02T00:00:00",
"last_revision_date": "2005-12-21T00:00:00",
"links": [
{
"title": "Bulletin de s\u00e9curit\u00e9 Mandriva MDKSA-2005:233 du 19 d\u00e9cembre 2005 :",
"url": "http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:233"
},
{
"title": "Liste des changements apport\u00e9s \u00e0 la version 2.0.55 :",
"url": "http://httpd.apache.org/security/vulnerabilities_20.html"
},
{
"title": "Le site de Apache :",
"url": "http://httpd.apache.org"
},
{
"title": "Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SR:2005:028 du 02 d\u00e9cembre 2005 :",
"url": "http://www.novell.com/linux/security/advisories/2005_28_sr.html"
}
],
"reference": "CERTA-2005-AVI-427",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2005-11-02T00:00:00.000000"
},
{
"description": "ajout des r\u00e9f\u00e9rences aux bulletins de s\u00e9curit\u00e9 SUSE SUSE-SR:2005:028 et Mandriva MDKSA-2005:233.",
"revision_date": "2005-12-21T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service"
}
],
"summary": "Une vuln\u00e9rabilit\u00e9 dans Apache 2.0 permet \u00e0 un utilisateur distant de\nprovoquer un d\u00e9ni de service.\n",
"title": "Vuln\u00e9rabilit\u00e9 de Apache 2.0",
"vendor_advisories": [
{
"published_at": null,
"title": "Liste des changements apport\u00e9s \u00e0 la version 2.0.55 d\u0027Apache",
"url": null
}
]
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…