cbcvebase.
CVE-2009-3094
published 2009-09-08

CVE-2009-3094: The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP…

PriorityP418low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
8.57%
94.5th percentile
The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.0.35 < 2.0.642.0.64
apachehttp_server>= 2.2.0 < 2.2.142.2.14
debianapache2< apache2 2.2.13-2 (bookworm)apache2 2.2.13-2 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora

CVSS provenance

nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.