PT-2004-1349 · Freebsd+5 · Freebsd+6

CVE-2004-0174

·

Publicado

2004-03-18

·

Atualizado

2024-02-15

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache versions 1.3.x through 1.3.29 Apache versions 1.4.x through 2.0.48
Description A denial of service issue occurs when a short-lived connection on a rarely-accessed listening socket causes a child to hold the accept mutex and block out new connections until another connection arrives on that rarely-accessed listening socket. This issue affects certain platforms, including some versions of AIX, Solaris, and Tru64, but does not affect FreeBSD or Linux.
Recommendations For Apache versions 1.3.x through 1.3.29, update to version 1.3.30 or later to resolve the issue. For Apache versions 1.4.x through 2.0.48, update to version 2.0.49 or later to resolve the issue. As a temporary workaround, consider restricting access to rarely-accessed listening sockets to minimize the risk of exploitation.

Correção

DoS

Improper Locking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2004-0174

Produtos afetados

Aix
Apache
Apache Http Server
Freebsd
Linux
Solaris
Tru64