CVE-2005-2970
published 2005-10-25CVE-2005-2970: Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
14.19%
96.2th percentile
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.36 < 2.0.55 | 2.0.55 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.0.55-1 (bookworm) | apache2 2.0.55-1 (bookworm) |
| fedoraproject | fedora_core | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache 2 vulnerability
vendor_ubuntu·2005-12-07
CVE-2005-2970 Apache 2 vulnerability
Title: Apache 2 vulnerability
Summary: Apache 2 vulnerability
A memory leak was found in the Apache 2 'worker' module in the
handling of aborted TCP connections. By repeatedly triggering this
situation, a remote attacker could drain all available memory, which
eventually led to a Denial of Service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-10-25·CVSS 5.0
CVE-2005-2970 [MEDIUM] security flaw
security flaw
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
Debian
CVE-2005-2970: apache2 - Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances,...
vendor_debian·2005·CVSS 5.0
CVE-2005-2970 [MEDIUM] CVE-2005-2970: apache2 - Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances,...
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
Scope: local
bookworm: resolved (fixed in 2.0.55-1)
bullseye: resolved (fixed in 2.0.55-1)
forky: resolved (fixed in 2.0.55-1)
sid: resolved (fixed in 2.0.55-1)
trixie: resolved (fixed in 2.0.55-1)
GHSA
GHSA-q8m3-9hrv-x6fg: Memory leak in the worker MPM (worker
ghsa_unreviewed·2022-05-01
CVE-2005-2970 [MEDIUM] CWE-770 GHSA-q8m3-9hrv-x6fg: Memory leak in the worker MPM (worker
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
OSV
CVE-2005-2970: Memory leak in the worker MPM (worker
osv·2005-10-25·CVSS 5.0
CVE-2005-2970 [MEDIUM] CVE-2005-2970: Memory leak in the worker MPM (worker
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-2970 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2005-2970 [MEDIUM] CVE-2005-2970 security flaw
CVE-2005-2970 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
Bugzilla
CVE-2005-2970, CVE-2005-3352, CVE-2005-3357 Apache httpd multiple security issues
bugzilla·2005-12-09·CVSS 7.5
CVE-2005-2970 [HIGH] CVE-2005-2970, CVE-2005-3352, CVE-2005-3357 Apache httpd multiple security issues
CVE-2005-2970, CVE-2005-3352, CVE-2005-3357 Apache httpd multiple security issues
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20051012 Netscape/8.0.4
Description of problem:
05.49.32 CVE: CVE-2005-2970
Platform: Cross Platform
Title: Apache MPM Worker.C Denial of Service
Description: Apache web-server is prone to a memory leak due to a flaw
in the "worker.c" file, causing a denial of service vulnerability.
Apache versions earlier than 2.0.55 are vulnerable.
Ref: http://www.apache.org/dist/httpd/Announcement2.0.html
Version-Release number of selected component (if applicable):
How reproducible:
Didn't try
Additional info:
Discussion:
New issue: CVE-2005-3352 cross-site scripting flaw in mod_imap
Ref: Fedora Core: Bug #175714
Ref
Bugzilla
CVE-2005-2970 httpd worker MPM memory consumption DoS
bugzilla·2005-11-25·CVSS 5.0
CVE-2005-2970 [MEDIUM] CVE-2005-2970 httpd worker MPM memory consumption DoS
CVE-2005-2970 httpd worker MPM memory consumption DoS
fc5 tracking bug
+++ This bug was initially created as a clone of Bug #171756 +++
Memory leak in the worker MPM (worker.c) for Apache 2, in certain
circumstances, allows remote attackers to cause a denial of service
(memory consumption) via aborted connections, which prevents the
memory for the transaction pool from being reused for other
connections.
-- Additional comment from [email protected] on 2005-10-25 18:06 EST --
This issue should also affect FC3
Discussion:
This is fixed in the FC5test2 httpd package. (fixed since 2.1.9 on the 2.1.x
branch)
Bugzilla
CVE-2005-2970 httpd worker MPM memory consumption DoS
bugzilla·2005-10-25·CVSS 5.0
CVE-2005-2970 [MEDIUM] CVE-2005-2970 httpd worker MPM memory consumption DoS
CVE-2005-2970 httpd worker MPM memory consumption DoS
+++ This bug was initially created as a clone of Bug #171756 +++
Memory leak in the worker MPM (worker.c) for Apache 2, in certain
circumstances, allows remote attackers to cause a denial of service
(memory consumption) via aborted connections, which prevents the
memory for the transaction pool from being reused for other
connections.
Discussion:
This issue should also affect FC3
---
From User-Agent: XML-RPC
httpd-2.0.54-10.3 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
---
From User-Agent: XML-RPC
httpd-2.0.54-10.3 has been pushed for FC4, which should resolve this issue. If these problems are still present in thi
Bugzilla
CVE-2005-2970 httpd worker MPM memory consumption DoS
bugzilla·2005-10-25·CVSS 5.0
CVE-2005-2970 [MEDIUM] CVE-2005-2970 httpd worker MPM memory consumption DoS
CVE-2005-2970 httpd worker MPM memory consumption DoS
Memory leak in the worker MPM (worker.c) for Apache 2, in certain
circumstances, allows remote attackers to cause a denial of service
(memory consumption) via aborted connections, which prevents the
memory for the transaction pool from being reused for other
connections.
Discussion:
This issue should also affect RHEL3
---
downgraded to low severity, this issue requires the exploitation of a race
condition which will be difficult, and in addition will not even cause a DoS
unless using the non-default worker MPM.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the u
http://mail-archives.apache.org/mod_mbox/httpd-cvs/200509.mbox/%3C20051001110218.40692.qmail%40minotaur.apache.org%3Ehttp://rhn.redhat.com/errata/RHSA-2006-0159.htmlhttp://secunia.com/advisories/16559http://secunia.com/advisories/17923http://secunia.com/advisories/18161http://secunia.com/advisories/18333http://secunia.com/advisories/18585http://securitytracker.com/id?1015093http://svn.apache.org/viewcvs?rev=292949&view=revhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:233http://www.novell.com/linux/security/advisories/2005_28_sr.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.htmlhttp://www.securityfocus.com/archive/1/425399/100/0/threadedhttp://www.securityfocus.com/bid/15762https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10043https://www.ubuntu.com/usn/usn-225-1/http://mail-archives.apache.org/mod_mbox/httpd-cvs/200509.mbox/%3C20051001110218.40692.qmail%40minotaur.apache.org%3Ehttp://rhn.redhat.com/errata/RHSA-2006-0159.htmlhttp://secunia.com/advisories/16559http://secunia.com/advisories/17923http://secunia.com/advisories/18161http://secunia.com/advisories/18333http://secunia.com/advisories/18585http://securitytracker.com/id?1015093http://svn.apache.org/viewcvs?rev=292949&view=revhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:233http://www.novell.com/linux/security/advisories/2005_28_sr.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.htmlhttp://www.securityfocus.com/archive/1/425399/100/0/threadedhttp://www.securityfocus.com/bid/15762https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10043https://www.ubuntu.com/usn/usn-225-1/
2005-10-25
Published