CVE-2004-2680
published 2004-12-31CVE-2004-2680: mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to…
PriorityP419medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.26%
90.0th percentile
mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mod_python | <= 3.1.4 | — |
| debian | libapache2-mod-python | < libapache2-mod-python 3.2.8-1 (bookworm) | libapache2-mod-python 3.2.8-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hjgf-wjp7-2h46: mod_python (libapache2-mod-python) 3
ghsa_unreviewed·2022-04-29
CVE-2004-2680 [MEDIUM] GHSA-hjgf-wjp7-2h46: mod_python (libapache2-mod-python) 3
mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
OSV
CVE-2004-2680: mod_python (libapache2-mod-python) 3
osv·2004-12-31·CVSS 5.0
CVE-2004-2680 [MEDIUM] CVE-2004-2680: mod_python (libapache2-mod-python) 3
mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
Ubuntu
mod_python vulnerability
vendor_ubuntu·2007-03-06
CVE-2004-2680 mod_python vulnerability
Title: mod_python vulnerability
Summary: mod_python vulnerability
Miles Egan discovered that mod_python, when used in output filter mode,
did not handle output larger than 16384 bytes, and would display freed
memory, possibly disclosing private data. Thanks to Jim Garrison of the
Software Freedom Law Center for identifying the original bug as a
security vulnerability.
Instructions: After a standard system upgrade you need to restart Apache to effect the
necessary changes.
Red Hat
mod_python arbitrary data disclosure flaw
vendor_redhat·2004-04-16·CVSS 5.0
CVE-2004-2680 [MEDIUM] mod_python arbitrary data disclosure flaw
mod_python arbitrary data disclosure flaw
mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. We no longer plan to fix this flaw in Red Hat Enterprise Linux 4.
Package: mod_python (Red Hat Enterprise Linux 4) - Will not fix
Package: mod_python (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2004-2680: libapache2-mod-python - mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle wh...
vendor_debian·2004·CVSS 5.0
CVE-2004-2680 [MEDIUM] CVE-2004-2680: libapache2-mod-python - mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle wh...
mod_python (libapache2-mod-python) 3.1.4 and earlier does not properly handle when output filters process more than 16384 bytes, which can cause filter.read to return portions of previously freed memory.
Scope: local
bookworm: resolved (fixed in 3.2.8-1)
bullseye: resolved (fixed in 3.2.8-1)
forky: resolved (fixed in 3.2.8-1)
sid: resolved (fixed in 3.2.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-2680 mod_python arbitrary data disclosure flaw
bugzilla·2007-12-20·CVSS 5.0
CVE-2004-2680 [MEDIUM] CVE-2004-2680 mod_python arbitrary data disclosure flaw
CVE-2004-2680 mod_python arbitrary data disclosure flaw
------- Comment From [email protected] 2011-01-31 15:05 EDT-------
Did this make it into 4.9?
------- Comment From [email protected] 2011-02-17 17:27 EDT-------
Since I don't see an updated mod_python package on RHN in the RHEL 4 beta channel, I don't expect this made 4.9 after all. The original submitter seems to have left IBM somewhere along the four years this bug was around though I am sure we can probably find someone else to verify the fix if there is one. For the moment, I am closing this as WILL_NOT_FIX. Thanks.
Discussion:
Hello,
This is currently in accepted state for RHEL 4.9.
Thank You
Joe Kachuck
---
(In reply to comment #12)
> This is currently in accepted state for RHEL 4.9.
This bug is *proposed* for
Bugzilla
CVE-2004-2680 mod_python arbitrary data disclosure flaw
bugzilla·2007-03-05·CVSS 5.0
CVE-2004-2680 [MEDIUM] CVE-2004-2680 mod_python arbitrary data disclosure flaw
CVE-2004-2680 mod_python arbitrary data disclosure flaw
A rather old mod_python flaw has recently been brought to our attention by Kees
Cook from Ubuntu.
This flaw is described here:
http://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%[email protected]%3e
This flaw also affects RHEL2.1 and RHEL3.
Discussion:
Created attachment 149298
Upstream patch
---
I'm not convinced this should be considered a security issue.
The bug in question can only triggered by use of an output filter; such an
output filter could already execute arbitrary code with the privileges of the
"apache" user.
---
That was my initial impression as well, but after thinking about this flaw for a
bit, it is possible for a remote users to leverage this to expose rand
http://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%3c6DCA8C14-8FFA-11D8-8B4E-000A95B0D772%40pixar.com%3ehttp://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%3cCD485B27-8F3E-11D8-934B-000A95B0D772%40pixar.com%3ehttp://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%3cEB279100-9000-11D8-8B4E-000A95B0D772%40pixar.com%3ehttp://secunia.com/advisories/24418http://secunia.com/advisories/24424http://svn.apache.org/viewvc/httpd/mod_python/trunk/src/filterobject.c?r1=102649&r2=103561&pathrev=103561http://www.securityfocus.com/archive/1/462185/100/0/threadedhttp://www.securityfocus.com/bid/22849http://www.ubuntu.com/usn/usn-430-1http://www.vupen.com/english/advisories/2007/0846https://exchange.xforce.ibmcloud.com/vulnerabilities/14751https://issues.rpath.com/browse/RPL-1105https://launchpad.net/bugs/89308http://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%3c6DCA8C14-8FFA-11D8-8B4E-000A95B0D772%40pixar.com%3ehttp://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%3cCD485B27-8F3E-11D8-934B-000A95B0D772%40pixar.com%3ehttp://mail-archives.apache.org/mod_mbox/httpd-python-dev/200404.mbox/%3cEB279100-9000-11D8-8B4E-000A95B0D772%40pixar.com%3ehttp://secunia.com/advisories/24418http://secunia.com/advisories/24424http://svn.apache.org/viewvc/httpd/mod_python/trunk/src/filterobject.c?r1=102649&r2=103561&pathrev=103561http://www.securityfocus.com/archive/1/462185/100/0/threadedhttp://www.securityfocus.com/bid/22849http://www.ubuntu.com/usn/usn-430-1http://www.vupen.com/english/advisories/2007/0846https://exchange.xforce.ibmcloud.com/vulnerabilities/14751https://issues.rpath.com/browse/RPL-1105https://launchpad.net/bugs/89308
2004-12-31
Published