CVE-2010-1623
published 2010-10-04CVE-2010-1623: Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
20.17%
97.2th percentile
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apr-util | <= 1.3.9 | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
| apache | apr-util | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_apache5.0LOW
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
APR-util vulnerability
vendor_ubuntu·2010-11-25
CVE-2010-1623 APR-util vulnerability
Title: APR-util vulnerability
It was discovered that APR-util did not properly handle memory when
destroying APR buckets. An attacker could exploit this and cause a denial
of service via memory exhaustion.
Instructions: After a standard system update you need to restart any applications using
APR-util, such as Subversion and Apache, to make all the necessary changes.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2010-11-25·CVSS 5.0
CVE-2010-1452 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
It was discovered that Apache's mod_cache and mod_dav modules incorrectly
handled requests that lacked a path. A remote attacker could exploit this
with a crafted request and cause a denial of service. This issue affected
Ubuntu 6.06 LTS, 8.04 LTS, 9.10 and 10.04 LTS. (CVE-2010-1452)
It was discovered that Apache did not properly handle memory when
destroying APR buckets. A remote attacker could exploit this with crafted
requests and cause a denial of service via memory exhaustion. This issue
affected Ubuntu 6.06 LTS and 10.10. (CVE-2010-1623)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
apr-util: high memory consumption in apr_brigade_split_line()
vendor_redhat·2010-10-01·CVSS 5.0
CVE-2010-1623 [MEDIUM] apr-util: high memory consumption in apr_brigade_split_line()
apr-util: high memory consumption in apr_brigade_split_line()
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
Debian
CVE-2010-1623: apache2 - Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in t...
vendor_debian·2010·CVSS 5.0
CVE-2010-1623 [MEDIUM] CVE-2010-1623: apache2 - Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in t...
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
Scope: local
bookworm: resolved (fixed in 2.2.16-3)
bullseye: resolved (fixed in 2.2.16-3)
forky: resolved (fixed in 2.2.16-3)
sid: resolved (fixed in 2.2.16-3)
trixie: resolved (fixed in 2.2.16-3)
Apache
Apache httpd: CVE-2010-1623
vendor_apache·CVSS 5.0
CVE-2010-1623 [LOW] Apache httpd: CVE-2010-1623
Apache httpd: CVE-2010-1623
A flaw was found in the apr_brigade_split_line() function of the bundled APR-util library, used to process non-SSL requests. A remote attacker could send requests, carefully crafting the timing of individual bytes, which would slowly consume memory, potentially leading to a denial of service. Reported to security team 2010-03-03 Issue public 2010-10-01 Update 2.2.17 released 2010-10-19 Update 2.0.64 released 2010-10-19 Affects 2.2.16, 2.2.15, 2.2.14, 2.2.13, 2.2.12, 2.2.11, 2.2.10, 2.2.9, 2.2.8, 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0, 2.0.63, 2.0.61, 2.0.59, 2.0.58, 2.0.55, 2.0.54, 2.0.53, 2.0.52, 2.0.51, 2.0.50, 2.0.49, 2.0.48, 2.0.47, 2.0.46, 2.0.45, 2.0.44, 2.0.43, 2.0.42, 2.0.40, 2.0.39, 2.0.37, 2.0.36, 2.0.35
Severity: low
GHSA
GHSA-2cc8-vf33-qm9m: Memory leak in the apr_brigade_split_line function in buckets/apr_brigade
ghsa_unreviewed·2022-05-13
CVE-2010-1623 [MEDIUM] CWE-119 GHSA-2cc8-vf33-qm9m: Memory leak in the apr_brigade_split_line function in buckets/apr_brigade
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
OSV
CVE-2010-1623: Memory leak in the apr_brigade_split_line function in buckets/apr_brigade
osv·2010-10-04·CVSS 5.0
CVE-2010-1623 [MEDIUM] CVE-2010-1623: Memory leak in the apr_brigade_split_line function in buckets/apr_brigade
Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.
No detection rules found.
No public exploits indexed.
HackerOne
Out-of-date Version (Apache)
hackerone·2019-12-02·CVSS 5.0
[MEDIUM] Out-of-date Version (Apache)
Out-of-date Version (Apache)
URL https://████████/
Identified Version 2.2.15 (contains 4 important and 10 other vulnerabilities)
Latest Version 2.2.31
Vulnerability Database Result is based on 27.10.2016 vulnerability database content.
Vulnerability Details
Link identified you are using an out-of-date version of Apache.
Impact
Since this is an old version of the software, it may be vulnerable to attacks.
Remedy
Please upgrade your installation of Apache to the latest stable version.
Remedy References
•Downloading the Apache HTTP Server
Known Vulnerabilities in this Version
Medium Apache mod_cache and mod_dav Request Handling Denial of Service Vulnerability
The mod_cache and mod_dav modules in the Apache HTTP Server allow remote attackers to cause a denial of service (process
Bugzilla
CVE-2010-1623 apr-util: high memory consumption in apr_brigade_split_line()
bugzilla·2010-10-05·CVSS 5.0
CVE-2010-1623 [MEDIUM] CVE-2010-1623 apr-util: high memory consumption in apr_brigade_split_line()
CVE-2010-1623 apr-util: high memory consumption in apr_brigade_split_line()
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1623 to
the following vulnerability:
The apr_brigade_split_line function in buckets/apr_brigade.c in the
Apache Portable Runtime Utility library (aka APR-util) before 1.3.10,
as used in the mod_reqtimeout module in the Apache HTTP Server and
other software, allows remote attackers to cause a denial of service
(memory consumption) via unspecified vectors.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1623
[2] http://security-tracker.debian.org/tracker/CVE-2010-1623
[3] http://svn.apache.org/viewvc?view=revision&revision=1003492
[4] http://svn.apache.org/viewvc?view=revision&revision=1003493
[5] http://svn.apache.org/view
http://blogs.sun.com/security/entry/cve_2010_1623_memory_leakhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049885.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049939.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.htmlhttp://marc.info/?l=bugtraq&m=130168502603566&w=2http://secunia.com/advisories/41701http://secunia.com/advisories/42015http://secunia.com/advisories/42361http://secunia.com/advisories/42367http://secunia.com/advisories/42403http://secunia.com/advisories/42537http://secunia.com/advisories/43211http://secunia.com/advisories/43285http://security-tracker.debian.org/tracker/CVE-2010-1623http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.627828http://svn.apache.org/viewvc?view=revision&revision=1003492http://svn.apache.org/viewvc?view=revision&revision=1003493http://svn.apache.org/viewvc?view=revision&revision=1003494http://svn.apache.org/viewvc?view=revision&revision=1003495http://svn.apache.org/viewvc?view=revision&revision=1003626http://ubuntu.com/usn/usn-1021-1http://www-01.ibm.com/support/docview.wss?uid=swg1PM31601http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3http://www.mandriva.com/security/advisories?name=MDVSA-2010:192http://www.redhat.com/support/errata/RHSA-2010-0950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0897.htmlhttp://www.securityfocus.com/bid/43673http://www.ubuntu.com/usn/USN-1022-1http://www.vupen.com/english/advisories/2010/2556http://www.vupen.com/english/advisories/2010/2557http://www.vupen.com/english/advisories/2010/2806http://www.vupen.com/english/advisories/2010/3064http://www.vupen.com/english/advisories/2010/3065http://www.vupen.com/english/advisories/2010/3074http://www.vupen.com/english/advisories/2011/0358https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76fb2224cc94c463a%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r688df6f16f141e966a0a47f817e559312b3da27886f59116a94b273d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad01d817195e6cc871cb1d73b207ca326379a20a6e7f30febaf56d24%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rad2acee3ab838b52c04a0698b1728a9a43467bf365bd481c993c535d%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/re2e23465bbdb17ffe109d21b4f192e6b58221cd7aa8797d530b4cd75%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12800http://blogs.sun.com/security/entry/cve_2010_1623_memory_leakhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049885.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-October/049939.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-11/msg00011.htmlhttp://marc.info/?l=bugtraq&m=130168502603566&w=2http://secunia.com/advisories/41701http://secunia.com/advisories/42015http://secunia.com/advisories/42361http://secunia.com/advisories/42367http://secunia.com/advisories/42403http://secunia.com/advisories/42537http://secunia.com/advisories/43211http://secunia.com/advisories/43285http://security-tracker.debian.org/tracker/CVE-2010-1623http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.627828http://svn.apache.org/viewvc?view=revision&revision=1003492http://svn.apache.org/viewvc?view=revision&revision=1003493http://svn.apache.org/viewvc?view=revision&revision=1003494http://svn.apache.org/viewvc?view=revision&revision=1003495http://svn.apache.org/viewvc?view=revision&revision=1003626http://ubuntu.com/usn/usn-1021-1http://www-01.ibm.com/support/docview.wss?uid=swg1PM31601http://www.apache.org/dist/apr/CHANGES-APR-UTIL-1.3http://www.mandriva.com/security/advisories?name=MDVSA-2010:192http://www.redhat.com/support/errata/RHSA-2010-0950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0896.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0897.htmlhttp://www.securityfocus.com/bid/43673http://www.ubuntu.com/usn/USN-1022-1http://www.vupen.com/english/advisories/2010/2556http://www.vupen.com/english/advisories/2010/2557http://www.vupen.com/english/advisories/2010/2806http://www.vupen.com/english/advisories/2010/3064http://www.vupen.com/english/advisories/2010/3065http://www.vupen.com/english/advisories/2010/3074http://www.vupen.com/english/advisories/2011/0358https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E
+ 18 more references
2010-10-04
Published