Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wvqw-w5hq-v4m4

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.

Ссылки

EPSS

Процентиль: 95%
0.2152
Средний

Дефекты

CWE-400

Связанные уязвимости

ubuntu
около 16 лет назад

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.

redhat
около 16 лет назад

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.

nvd
около 16 лет назад

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.

msrc
около 3 лет назад

Описание отсутствует

debian
около 16 лет назад

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy mo ...

EPSS

Процентиль: 95%
0.2152
Средний

Дефекты

CWE-400