CVE-2008-2364

Publication date 13 June 2008

Last updated 24 July 2024


Ubuntu priority

The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.

Read the notes from the security team

Status

Package Ubuntu Release Status
apache2 8.10 intrepid
Fixed 2.2.9-1
8.04 LTS hardy
Fixed 2.2.8-1ubuntu0.4
7.10 gutsy
Fixed 2.2.4-3ubuntu0.2
7.04 feisty Ignored end of life, was needed
6.06 LTS dapper
Fixed 2.0.55-4ubuntu2.4

Notes


kees

only a problem when the server being proxied is untrusted


jdstrand

PoC: http://svn.apache.org/viewvc/httpd/test/framework/trunk/t/security/CVE-2008-2364.t?revision=666283&view=markup

References

Related Ubuntu Security Notices (USN)

    • USN-731-1
    • Apache vulnerabilities
    • 10 March 2009

Other references