Описание
The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
Отчет
This issue did not affect the version of httpd as shipped with Red Hat Enterprise Linux 5.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 4 | httpd | Not affected | ||
| Red Hat Enterprise Linux 5 | httpd | Not affected | ||
| Red Hat Enterprise Linux 6 | httpd | Fixed | RHSA-2013:0512 | 20.02.2013 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | ant | Fixed | RHSA-2011:0897 | 22.06.2011 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | antlr | Fixed | RHSA-2011:0897 | 22.06.2011 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | cglib | Fixed | RHSA-2011:0897 | 22.06.2011 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | dom4j | Fixed | RHSA-2011:0897 | 22.06.2011 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | ecj3 | Fixed | RHSA-2011:0897 | 22.06.2011 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | glassfish-jsf | Fixed | RHSA-2011:0897 | 22.06.2011 |
| Red Hat JBoss Enterprise Web Server 1 for RHEL 5 | hibernate3 | Fixed | RHSA-2011:0897 | 22.06.2011 |
Показывать по
Дополнительная информация
Статус:
EPSS
2.6 Low
CVSS2
Связанные уязвимости
The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2. ...
The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.
ELSA-2013-0512: httpd security, bug fix, and enhancement update (LOW)
EPSS
2.6 Low
CVSS2