CVE-2009-2699

MEDIUM

Description

The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.

References

http://marc.info/?l=bugtraq&m=133355494609819&w=2

http://securitytracker.com/id?1022988

http://www.apache.org/dist/httpd/CHANGES_2.2.14

http://www.mandriva.com/security/advisories?name=MDVSA-2013:150

http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html

http://www.securityfocus.com/bid/36596

https://exchange.xforce.ibmcloud.com/vulnerabilities/53666

https://issues.apache.org/bugzilla/show_bug.cgi?id=47645

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E

Details

Source: MITRE

Published: 2009-10-13

Updated: 2018-10-30

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM