CVE-2004-0113
published 2004-03-29CVE-2004-0113: Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
9.90%
95.0th percentile
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| debian | apache2 | < apache2 2.0.52 (bookworm) | apache2 2.0.52 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2004-02-20·CVSS 5.0
CVE-2004-0113 [MEDIUM] security flaw
security flaw
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
Debian
CVE-2004-0113: apache2 - Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remo...
vendor_debian·2004·CVSS 5.0
CVE-2004-0113 [MEDIUM] CVE-2004-0113: apache2 - Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remo...
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
Scope: local
bookworm: resolved (fixed in 2.0.52)
bullseye: resolved (fixed in 2.0.52)
forky: resolved (fixed in 2.0.52)
sid: resolved (fixed in 2.0.52)
trixie: resolved (fixed in 2.0.52)
GHSA
GHSA-hq2q-rqpw-7wx5: Memory leak in ssl_engine_io
ghsa_unreviewed·2022-04-29
CVE-2004-0113 [MEDIUM] GHSA-hq2q-rqpw-7wx5: Memory leak in ssl_engine_io
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
OSV
CVE-2004-0113: Memory leak in ssl_engine_io
osv·2004-03-29·CVSS 5.0
CVE-2004-0113 [MEDIUM] CVE-2004-0113: Memory leak in ssl_engine_io
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
No detection rules found.
No public exploits indexed.
arXiv
Automated Code-centric Software Vulnerability Assessment: How Far Are We? An Empirical Study in C/C++
arxiv_fulltext·2024-08-03
Automated Code-centric Software Vulnerability Assessment: How Far Are We? An Empirical Study in C/C++
Automated Code-centric Software Vulnerability Assessment:
How Far Are We? An Empirical Study in C/C++
Anh The Nguyen
Independent Researcher Vietnam
[email protected]
Triet Huynh Minh Le
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide
Adelaide
Australia
Cyber Security Cooperative Research Centre, Australia
[email protected]
M. Ali Babar
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide
Adelaide
Australia
Cyber Security Cooperative Research Centre, Australia
[email protected]
## Abstract
Background:
The C/C++ languages hold significant importance in Software Engineering research because of their widespread use in practice.
Numerous studies have utilized Machin
arXiv
On the Use of Fine-grained Vulnerable Code Statements for Software Vulnerability Assessment Models
arxiv_fulltext·2022-03-16
On the Use of Fine-grained Vulnerable Code Statements for Software Vulnerability Assessment Models
On the Use of Fine-grained Vulnerable Code Statements for Software Vulnerability Assessment Models
Triet Huynh Minh Le
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide
Adelaide
Australia
[email protected]
M. Ali Babar
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide
Adelaide
Australia
Cyber Security Cooperative Research Centre, Australia
[email protected]
## Abstract
Many studies have developed Machine Learning (ML) approaches to detect Software Vulnerabilities (SVs) in functions and fine-grained code statements that cause such SVs.
However, there is little work on leveraging such detection outputs for data-driven SV assessment to give information about exploitability, impa
arXiv
DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning
arxiv_fulltext·2021-08-18
DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning
DeepCVA: Automated Commit-level Vulnerability Assessment with Deep Multi-task Learning
Triet Huynh Minh Le1,
David Hin12,
Roland Croft12 and
M. Ali Babar12
1CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide, Australia
2Cyber Security Cooperative Research Centre, Australia
\triet.h.le, david.hin, roland.croft, ali.babar\@adelaide.edu.au
## Abstract
It is increasingly suggested to identify Software Vulnerabilities (SVs) in code commits to give early warnings about potential security risks. However, there is a lack of effort to assess vulnerability-contributing commits right after they are detected to provide timely information about the exploitability, impact and severity of SVs. Such information is important to plan and prioritize the mitiga
arXiv
Cleaning the NVD: Comprehensive Quality Assessment, Improvements, and Analyses
arxiv_fulltext·2020-06-26
Cleaning the NVD: Comprehensive Quality Assessment, Improvements, and Analyses
[Cleaning the NVD]Cleaning the NVD: Comprehensive Quality Assessment, Improvements, and Analyses
Afsah Anwar
University of Central Florida
[email protected]
Ahmed Abusnaina
University of Central Florida
[email protected]
Songqing Chen
George Mason University
[email protected]
Frank Li
Georgia Institute of Technology
[email protected]
David Mohaisen
University of Central Florida
[email protected]
## Abstract
Vulnerability databases are vital sources of information on emergent software security concerns. Security professionals, from system administrators to developers to researchers, heavily depend on these databases to track vulnerabilities and analyze security trends. How reliable and accurate are these databases though?
In this paper, we explore this questio
Trendmicro
Drupal Bug Exploited to Deliver Monero-Mining Malware
blogs_trendmicro·2018-06-21·CVSS 9.8
CVE-2018-7602 [CRITICAL] Drupal Bug Exploited to Deliver Monero-Mining Malware
Malware
# Drupal Bug Exploited to Deliver Monero-Mining Malware
We were able to observe a series of network attacks exploiting, a security flaw (CVE-2018-7602) in the Drupal content management framework. For now, these attacks aim to turn affected systems into Monero-mining bots.
By: Smart Home Network Team, IoT Reputation Service Team
2018/06/21
Read time: ( words)
Save to Folio
We were able to observe a series of network attacks exploiting CVE-2018-7602, a security flaw in the Drupal content management framework. For now, these attacks aim to turn affected systems into Monero-mining bots. Of note are its ways of hiding behind the Tor network to elude detection and how it checks the affected system first before infecting it with a cryptocurrency-mining malware. While these attacks c
Recorded Future
Threat Actors Remember the Vulnerabilities We Forget
blogs_recorded_future·CVSS 5.0
[MEDIUM] Threat Actors Remember the Vulnerabilities We Forget
# Threat Actors Remember the Vulnerabilities We Forget
#### Key Takeaways
- Threat actors continue to exploit older vulnerabilities because they are left unpatched and can represent easy targets.
- Threat intelligence gathered from Recorded Future reveals that around 19 percent of exploited vulnerabilities mentioned on the dark web in the last six months were more than a year old.
- With the growing use of smart devices like mobile phones and the various products making up the internet of things, expect old vulnerabilities to continue to be exploited. Many of these products are insecure and run old and outdated software.
In an industry so concerned with prognostication, it’s common practice to treat the newest vulnerabilities, exploits, and other threats as the ones most urgently needin
Recorded Future
Threat Actors Remember the Vulnerabilities We Forget | Recorded Future
blogs_recorded_future·CVSS 5.0
[MEDIUM] Threat Actors Remember the Vulnerabilities We Forget | Recorded Future
## Threat Actors Remember the Vulnerabilities We Forget
## Key Takeaways
Threat actors continue to exploit older vulnerabilities because they are left unpatched and can represent easy targets.
Threat intelligence gathered from Recorded Future reveals that around 19 percent of exploited vulnerabilities mentioned on the dark web in the last six months were more than a year old.
With the growing use of smart devices like mobile phones and the various products making up the internet of things, expect old vulnerabilities to continue to be exploited. Many of these products are insecure and run old and outdated software.
In an industry so concerned with prognostication, it’s common practice to treat the newest vulnerabilities, exploits, and other threats as the ones most urgently needing att
Bugzilla
CVE-2004-0113 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2004-0113 [MEDIUM] CVE-2004-0113 security flaw
CVE-2004-0113 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000839http://issues.apache.org/bugzilla/show_bug.cgi?id=27106http://marc.info/?l=apache-cvs&m=107869699329638http://marc.info/?l=bugtraq&m=108034113406858&w=2http://marc.info/?l=bugtraq&m=108369640424244&w=2http://marc.info/?l=bugtraq&m=108731648532365&w=2http://security.gentoo.org/glsa/glsa-200403-04.xmlhttp://www.apacheweek.com/features/security-20http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:043http://www.osvdb.org/4182http://www.redhat.com/support/errata/RHSA-2004-084.htmlhttp://www.redhat.com/support/errata/RHSA-2004-182.htmlhttp://www.securityfocus.com/bid/9826http://www.trustix.org/errata/2004/0017https://exchange.xforce.ibmcloud.com/vulnerabilities/15419https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7035b7c9091c4b665a3b7205364775410646f12125d48e74e395f2ce%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/raa117ef183f0da9b3f46efbeaa66f7622bd68868a450cae4fd8ed594%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re028d61fe612b0908595d658b9b39e74bca56f2a1ed3c5f06b5ab571%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A876http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000839http://issues.apache.org/bugzilla/show_bug.cgi?id=27106http://marc.info/?l=apache-cvs&m=107869699329638http://marc.info/?l=bugtraq&m=108034113406858&w=2http://marc.info/?l=bugtraq&m=108369640424244&w=2http://marc.info/?l=bugtraq&m=108731648532365&w=2http://security.gentoo.org/glsa/glsa-200403-04.xmlhttp://www.apacheweek.com/features/security-20http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:043http://www.osvdb.org/4182http://www.redhat.com/support/errata/RHSA-2004-084.htmlhttp://www.redhat.com/support/errata/RHSA-2004-182.htmlhttp://www.securityfocus.com/bid/9826http://www.trustix.org/errata/2004/0017https://exchange.xforce.ibmcloud.com/vulnerabilities/15419https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7035b7c9091c4b665a3b7205364775410646f12125d48e74e395f2ce%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/raa117ef183f0da9b3f46efbeaa66f7622bd68868a450cae4fd8ed594%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re028d61fe612b0908595d658b9b39e74bca56f2a1ed3c5f06b5ab571%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A876
2004-03-29
Published