CVE-2010-0010
published 2010-02-02CVE-2010-0010: Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote…
PriorityP347medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
43.42%
98.6th percentile
Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | <= 1.3.41 | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
| apache | http_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache HTTP Server up to 1.3.3 mod_proxy ap_proxy_send_fb numeric error (Nessus ID 44589 / ID 86868)
vuldb·2026-04-29·CVSS 6.8
CVE-2010-0010 [MEDIUM] Apache HTTP Server up to 1.3.3 mod_proxy ap_proxy_send_fb numeric error (Nessus ID 44589 / ID 86868)
A vulnerability classified as critical was found in Apache HTTP Server up to 1.3.3. Impacted is the function ap_proxy_send_fb of the component mod_proxy. Such manipulation leads to numeric error.
This vulnerability is documented as CVE-2010-0010. The attack can be executed remotely. Additionally, an exploit exists.
Upgrading the affected component is advised.
GHSA
GHSA-8xvp-wq7g-q2vj: Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util
ghsa_unreviewed·2022-05-02
CVE-2010-0010 [MEDIUM] GHSA-8xvp-wq7g-q2vj: Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util
Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0010 httpd (v1.3): mod_proxy overflow on 64-bit systems
bugzilla·2010-02-03·CVSS 6.8
CVE-2010-0010 [MEDIUM] CVE-2010-0010 httpd (v1.3): mod_proxy overflow on 64-bit systems
CVE-2010-0010 httpd (v1.3): mod_proxy overflow on 64-bit systems
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0010 to
the following vulnerability:
Integer overflow in the ap_proxy_send_fb function in
proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before
1.3.42 on 64-bit platforms allows remote origin servers to cause a
denial of service (daemon crash) or possibly execute arbitrary code
via a large chunk size that triggers a heap-based buffer overflow.
Upstream patch:
http://svn.apache.org/viewvc?view=revision&revision=896842
Discussion:
This issue did not affect the versions of the httpd package,
as shipped with Red Hat Enterprise Linux 3, 4, and 5.
For complete list of vulnerable Apache httpd server versions
proceed to upstream security dedicated p
Bugzilla
CVE-2010-0010 rhn-apache: buffer overflow via integer overflow vulnerability on 64bit platforms
bugzilla·2010-01-27·CVSS 6.8
CVE-2010-0010 [MEDIUM] CVE-2010-0010 rhn-apache: buffer overflow via integer overflow vulnerability on 64bit platforms
CVE-2010-0010 rhn-apache: buffer overflow via integer overflow vulnerability on 64bit platforms
It was reported [1] that mod_proxy in apache 1.3.x is vulnerable to a buffer overflow on the heap via an integer overflow vulnerability. In the ap_proxy_send_fb() function (in src/modules/proxy/proxy_util.c), the server will convert received data to a long type, and if there is a positive chunk size, will convert the long to an int type, resulting in an integer overflow on 64bit platforms.
[1] http://marc.info/?l=full-disclosure&m=126461496425954&w=2
Discussion:
This shouldn't affect Apache 2. The code in question isn't there, and the reproducer does nothing, Apache 2 appears to gracefully handle the large body.
---
I'm marking the severity of this flaw to low. It only affects rhn satellit
http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0589.htmlhttp://blog.pi3.com.pl/?p=69http://httpd.apache.org/dev/dist/CHANGES_1.3.42http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlhttp://marc.info/?l=bugtraq&m=130497311408250&w=2http://packetstormsecurity.org/1001-exploits/modproxy-overflow.txthttp://secunia.com/advisories/38319http://secunia.com/advisories/39656http://site.pi3.com.pl/adv/mod_proxy.txthttp://www.securityfocus.com/archive/1/509185/100/0/threadedhttp://www.securityfocus.com/bid/37966http://www.securitytracker.com/id?1023533http://www.vupen.com/english/advisories/2010/0240http://www.vupen.com/english/advisories/2010/1001https://exchange.xforce.ibmcloud.com/vulnerabilities/55941https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7923http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0589.htmlhttp://blog.pi3.com.pl/?p=69http://httpd.apache.org/dev/dist/CHANGES_1.3.42http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00006.htmlhttp://marc.info/?l=bugtraq&m=130497311408250&w=2http://packetstormsecurity.org/1001-exploits/modproxy-overflow.txthttp://secunia.com/advisories/38319http://secunia.com/advisories/39656http://site.pi3.com.pl/adv/mod_proxy.txthttp://www.securityfocus.com/archive/1/509185/100/0/threadedhttp://www.securityfocus.com/bid/37966http://www.securitytracker.com/id?1023533http://www.vupen.com/english/advisories/2010/0240http://www.vupen.com/english/advisories/2010/1001https://exchange.xforce.ibmcloud.com/vulnerabilities/55941https://lists.apache.org/thread.html/r2295080a257bad27ea68ca0af12fc715577f9e84801eae116a33107e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb7c64aeea604bf948467d9d1cab8ff23fa7d002be1964bcc275aae7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7923
2010-02-02
Published