Search

published date: February 9, 2005

CVE-2004-0942 : Denial of Service Vulnerability

Description

Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.

Product(s):

  • Apache HTTP Server
  • Apache Software Foundation Apache HTTP Server
  • Apache Software Foundation Apache HTTP Server 0.8.11
  • Apache Software Foundation Apache HTTP Server 0.8.14
  • Apache Software Foundation Apache HTTP Server 1.0.2
  • Apache Software Foundation Apache HTTP Server 1.0.3

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-0942, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-0942 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?