CVE-2005-2728Apache Http Server vulnerability

8 documents8 sources
Severity
5.0MEDIUMNVD
EPSS
61.8%
top 1.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 30
Latest updateMay 3

Description

The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDapache/http_server23 versions+22

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5rc2-352q-326v: The byte-range filter in Apache 22022-05-03
OSV
CVE-2005-2728: The byte-range filter in Apache 22005-08-30
CVEList
CVE-2005-2728: The byte-range filter in Apache 22005-08-29

📋Vendor Advisories

3
Ubuntu
Apache 2 vulnerabilities2005-09-07
Debian
CVE-2005-2728: apache2 - The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cau...2005
Red Hat
security flaw2004-07-07

💬Community

1
Bugzilla
CVE-2005-2728 security flaw2018-08-16
CVE-2005-2728 — Apache Http Server vulnerability | cvebase