CVE-2005-2970

Severity
5.0MEDIUM
EPSS
20.8%
top 4.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateMay 1

Description

Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages6 packages

NVDapache/http_server2.0.362.0.55
Debianapache2< 2.0.55-1+3

Also affects: Ubuntu Linux 4.10, 5.04, 5.10

🔴Vulnerability Details

3
GHSA
GHSA-q8m3-9hrv-x6fg: Memory leak in the worker MPM (worker2022-05-01
CVEList
CVE-2005-2970: Memory leak in the worker MPM (worker2005-10-25
OSV
CVE-2005-2970: Memory leak in the worker MPM (worker2005-10-25

📋Vendor Advisories

3
Ubuntu
Apache 2 vulnerability2005-12-07
Red Hat
security flaw2005-10-25
Debian
CVE-2005-2970: apache2 - Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances,...2005

💬Community

5
Bugzilla
CVE-2005-2970 security flaw2018-08-16
Bugzilla
CVE-2005-2970, CVE-2005-3352, CVE-2005-3357 Apache httpd multiple security issues2005-12-09
Bugzilla
CVE-2005-2970 httpd worker MPM memory consumption DoS2005-11-25
Bugzilla
CVE-2005-2970 httpd worker MPM memory consumption DoS2005-10-25
Bugzilla
CVE-2005-2970 httpd worker MPM memory consumption DoS2005-10-25
CVE-2005-2970 (MEDIUM CVSS 5) | Memory leak in the worker MPM (work | cvebase.io