CVE-2008-2364
published 2008-06-13CVE-2008-2364: The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
12.71%
95.8th percentile
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.0.35 < 2.0.64 | 2.0.64 |
| apache | http_server | >= 2.2.0 < 2.2.9 | 2.2.9 |
| apache | httpd | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.2.9-1 (bookworm) | apache2 2.2.9-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_apache5.0
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2009-03-10·CVSS 4.3
CVE-2007-6203 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the method specifier header from
an HTTP request when it is returned in an error message, which could result in
browsers becoming vulnerable to cross-site scripting attacks when processing the
output. With cross-site scripting vulnerabilities, if a user were tricked into
viewing server output during a crafted server request, a remote attacker could
exploit this to modify the contents, or steal confidential data (such as
passwords), within the same domain. This issue only affected Ubuntu 6.06 LTS and
7.10. (CVE-2007-6203)
It was discovered that Apache was vulnerable to a cross-site request forgery
(CSRF) in the mod_proxy_balancer balancer manager. If an Apache administrator
were t
Red Hat
httpd: mod_proxy_http DoS via excessive interim responses from the origin server
vendor_redhat·2008-06-10·CVSS 5.0
CVE-2008-2364 [MEDIUM] httpd: mod_proxy_http DoS via excessive interim responses from the origin server
httpd: mod_proxy_http DoS via excessive interim responses from the origin server
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
A flaw was found in the mod_proxy module. An attacker who has control of a web server to which requests are being proxied could cause a limited denial of service due to CPU consumption and stack exhaustion. (CVE-2008-2364)
Statement: Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2008-2364
The Red Hat Product Security
Debian
CVE-2008-2364: apache2 - The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy...
vendor_debian·2008·CVSS 5.0
CVE-2008-2364 [MEDIUM] CVE-2008-2364: apache2 - The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy...
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
Scope: local
bookworm: resolved (fixed in 2.2.9-1)
bullseye: resolved (fixed in 2.2.9-1)
forky: resolved (fixed in 2.2.9-1)
sid: resolved (fixed in 2.2.9-1)
trixie: resolved (fixed in 2.2.9-1)
Apache
Apache httpd: CVE-2008-2364
vendor_apache·CVSS 5.0
CVE-2008-2364 Apache httpd: CVE-2008-2364
Apache httpd: CVE-2008-2364
A flaw was found in the handling of excessive interim responses from an origin server when using mod_proxy_http. A remote attacker could cause a denial of service or high memory usage. Reported to security team 2008-05-29 Issue public 2008-06-10 Update 2.0.64 released 2010-10-19 Update 2.2.9 released 2008-06-14 Affects 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0, 2.0.63, 2.0.61, 2.0.59, 2.0.58, 2.0.55, 2.0.54, 2.0.53, 2.0.52, 2.0.51, 2.0.50, 2.0.49, 2.0.48, 2.0.47, 2.0.46, 2.0.45, 2.0.44, 2.0.43, 2.0.42, 2.0.40, 2.0.39, 2.0.37, 2.0.36, 2.0.35
Severity: moderate
GHSA
GHSA-jjpp-hx4r-hqpc: The ap_proxy_http_process_response function in mod_proxy_http
ghsa_unreviewed·2022-05-01
CVE-2008-2364 [MEDIUM] CWE-770 GHSA-jjpp-hx4r-hqpc: The ap_proxy_http_process_response function in mod_proxy_http
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
OSV
CVE-2008-2364: The ap_proxy_http_process_response function in mod_proxy_http
osv·2008-06-13·CVSS 5.0
CVE-2008-2364 [MEDIUM] CVE-2008-2364: The ap_proxy_http_process_response function in mod_proxy_http
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-2939 httpd: mod_proxy_ftp globbing XSS
bugzilla·2008-08-07·CVSS 5.0
CVE-2008-2939 [MEDIUM] CVE-2008-2939 httpd: mod_proxy_ftp globbing XSS
CVE-2008-2939 httpd: mod_proxy_ftp globbing XSS
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-2939 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via wildcards in a pathname in an FTP URI.
This is low severity as it requires proxying to be enabled, mod_proxy-ftp to be
enabled to support ftp-over-httpd.
http://httpd.apache.org/security/vulnerabilities_22.html
Discussion:
Release note added. If any revisions are required, please set the
"requires_release_notes" flag to "?" and edit the "Release Notes" field accordin
Bugzilla
Security: CVE-2008-2364, CVE-2007-6420: Apache 2.2.9 released, offers significant performance/security improvements
bugzilla·2008-07-04·CVSS 4.3
CVE-2008-2364 [MEDIUM] Security: CVE-2008-2364, CVE-2007-6420: Apache 2.2.9 released, offers significant performance/security improvements
Security: CVE-2008-2364, CVE-2007-6420: Apache 2.2.9 released, offers significant performance/security improvements
Description of problem: Fedora 8 and 9 use Apache 2.2.8. There are significant
improvements in 2.2.9 that I have seen on Windows that should also improve the
performance on Fedora.
Version-Release number of selected component (if applicable): 2.2.9
How reproducible: Always
Additional info: See http://www.apache.org/dist/httpd/CHANGES_2.2.9 for list
of improvements. This also fixes CVE-2007-6420 and CVE-2008-2364, the latter
probably was the one that fixed my high memory usage problem and caused an
unintentional DOS on a slow Windows server running 2.2.8.
Discussion:
Additionally, there are two significant security flaws with this, so much so
that I decided to change
Bugzilla
CVE-2008-2364 httpd: mod_proxy_http DoS via excessive interim responses from the origin server
bugzilla·2008-06-16·CVSS 5.0
CVE-2008-2364 [MEDIUM] CVE-2008-2364 httpd: mod_proxy_http DoS via excessive interim responses from the origin server
CVE-2008-2364 httpd: mod_proxy_http DoS via excessive interim responses from the origin server
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-2364 to the following vulnerability:
The ap_proxy_http_process_response function in mod_proxy_http.c in the
mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the
number of forwarded interim responses, which allows remote HTTP servers to
cause a denial of service (memory consumption) via a large number of interim
responses.
Fixed upstream in: 2.2.9
http://www.apache.org/dist/httpd/CHANGES_2.2.9
Upsteam patch in 2.2.x branch:
http://svn.apache.org/viewvc?view=rev&revision=666154
Other references:
http://www.securityfocus.com/bid/29653
http://www.frsirt.com/english/advisories/2008/1798
http://secunia.c
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://marc.info/?l=bugtraq&m=123376588623823&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://rhn.redhat.com/errata/RHSA-2008-0967.htmlhttp://secunia.com/advisories/30621http://secunia.com/advisories/31026http://secunia.com/advisories/31404http://secunia.com/advisories/31416http://secunia.com/advisories/31651http://secunia.com/advisories/31904http://secunia.com/advisories/32222http://secunia.com/advisories/32685http://secunia.com/advisories/32838http://secunia.com/advisories/33156http://secunia.com/advisories/33797http://secunia.com/advisories/34219http://secunia.com/advisories/34259http://secunia.com/advisories/34418http://security.gentoo.org/glsa/glsa-200807-06.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1http://support.apple.com/kb/HT3216http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&r2=666153&pathrev=666154http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328http://www-01.ibm.com/support/docview.wss?uid=swg27008517http://www-1.ibm.com/support/docview.wss?uid=swg1PK67579http://www.mandriva.com/security/advisories?name=MDVSA-2008:195http://www.mandriva.com/security/advisories?name=MDVSA-2008:237http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0966.htmlhttp://www.securityfocus.com/archive/1/494858/100/0/threadedhttp://www.securityfocus.com/archive/1/498567/100/0/threadedhttp://www.securityfocus.com/bid/29653http://www.securityfocus.com/bid/31681http://www.securitytracker.com/id?1020267http://www.ubuntu.com/usn/USN-731-1http://www.vupen.com/english/advisories/2008/1798http://www.vupen.com/english/advisories/2008/2780http://www.vupen.com/english/advisories/2009/0320https://exchange.xforce.ibmcloud.com/vulnerabilities/42987https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8c9983f1172a3415f915ddb7e14de632d2d0c326eb1285755a024165%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11713https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6084https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9577https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00055.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-August/msg00153.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://marc.info/?l=bugtraq&m=123376588623823&w=2http://marc.info/?l=bugtraq&m=125631037611762&w=2http://rhn.redhat.com/errata/RHSA-2008-0967.htmlhttp://secunia.com/advisories/30621http://secunia.com/advisories/31026http://secunia.com/advisories/31404http://secunia.com/advisories/31416http://secunia.com/advisories/31651http://secunia.com/advisories/31904http://secunia.com/advisories/32222http://secunia.com/advisories/32685http://secunia.com/advisories/32838http://secunia.com/advisories/33156http://secunia.com/advisories/33797http://secunia.com/advisories/34219http://secunia.com/advisories/34259http://secunia.com/advisories/34418http://security.gentoo.org/glsa/glsa-200807-06.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1http://support.apple.com/kb/HT3216http://svn.apache.org/viewvc/httpd/httpd/trunk/modules/proxy/mod_proxy_http.c?r1=666154&r2=666153&pathrev=666154http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328http://www-01.ibm.com/support/docview.wss?uid=swg27008517http://www-1.ibm.com/support/docview.wss?uid=swg1PK67579http://www.mandriva.com/security/advisories?name=MDVSA-2008:195http://www.mandriva.com/security/advisories?name=MDVSA-2008:237http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0966.htmlhttp://www.securityfocus.com/archive/1/494858/100/0/threadedhttp://www.securityfocus.com/archive/1/498567/100/0/threaded
+ 32 more references
2008-06-13
Published