Search

published date: August 6, 2004

CVE-2004-0492 : Denial of Service Vulnerability

Description

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

Product(s):

  • Apache Software Foundation Apache HTTP Server 1.3.26
  • Apache Software Foundation Apache HTTP Server 1.3.27
  • Apache Software Foundation Apache HTTP Server 1.3.28
  • Apache Software Foundation Apache HTTP Server 1.3.29
  • Apache Software Foundation Apache HTTP Server 1.3.31
  • HP VirtualVault 11.0.4

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-0492, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-0492 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?